{"publisher":"Servnet","url":"https://www.servnetuk.com/research/uk-data-breach-statistics-2026","study":"uk-data-breach-trends-2026","title":"UK data breach trends: personal data breach reports to the ICO, 2019-2025","attribution":"Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0.","meta":{"publisher_of_source":"Information Commissioner's Office (ICO)","source_page":"https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/","quarters":["2019-Q1","2025-Q4"],"attribution_line":"Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0.","rounding":"Percentages are computed from exact counts and rounded half away from zero (\"half-up\") to one decimal place; rankings use the unrounded ratios.","source_licence":{"licence":"Open Government Licence v3.0","url":"https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/","attribution":"Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0.","ico_statement":"All text content on this website is available under the Open Government Licence (OGL) v3.0, except where otherwise stated.","dataset_note":"The ICO data files carry no licence statement of their own and the dataset page states no exception; attribution follows the ICO's OGL wording."},"dataset_licence":{"licence":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","note":"Applies to this compilation and the derived tables; the underlying ICO data remains under OGL v3.0 and must keep the ICO attribution."}},"builtFrom":{"file":"https://ico.org.uk/media2/ng3pl21l/data-security-incidents-trends-q1-2019-to-q4-2025.xlsx","sha256":"4179efdaa3ea4edbe41caef1ad3174f6d2a1454221138c588df5c2d8baaa7fa1","retrieved":"2026-09-19T12:47:41Z","reports":77222},"download":{"csv":"/research/uk-data-breach-trends-2026.csv","readme":"/research/uk-data-breach-trends-2026-README.txt","rows":7619,"reports":77222},"definitions":{"unit":"One personal data breach report received by the ICO (a case), not one breach and not one organisation.","large_band_people":10000,"large_band_note":"Reports in the ICO bands \"10k to 100k\" and \"100k and above\": estimated at the time of reporting to affect 10,000 or more people. The ICO advises organisations \"to indicate the maximum number that may be affected\".","notification_window_hours":72,"notification_note":"UK GDPR: notify the ICO \"within 72 hours of becoming aware of the breach, where feasible\".","within_72_hours_bands":["Less than 24 hours","24 hours to 72 hours"],"min_base_for_growth":100,"min_reports_for_sector_share_ranking":100,"q1_q3_check":"Compares the first three quarters of each year only, leaving out the provisional 2025-Q4.","investigation_pursued_share":"Of reports with an outcome recorded (reports minus \"Not Yet Assigned\"), the share recorded as \"Investigation Pursued\". The ICO notes this \"may not necessarily lead to a full investigation\"."},"headline":{"reports2019to2025":77222,"reports2025":13457,"change2025vs2024Pct":10.3,"highestQuarter":{"quarter":"2025-Q4","reports":3677},"ransomware2025":617,"ransomwarePeakYear":{"year":2023,"ransomware":1253},"cyberShareIco2025Pct":23.4,"alwaysCyberShare2025Pct":24.2,"latestQuarter":"2025-Q4"},"findings":{"totals_by_quarter":{"title":"Personal data breach reports received by the ICO, per quarter","unit":"reports (cases)","values":[{"quarter":"2019-Q1","reports":3372,"flag":"ICO: \"The data starts at Q2 2019 as incidents were recorded differently prior to this period.\" The file nonetheless contains 2019-Q1; it is shown but flagged."},{"quarter":"2019-Q2","reports":3077},{"quarter":"2019-Q3","reports":3002},{"quarter":"2019-Q4","reports":2808},{"quarter":"2020-Q1","reports":2644},{"quarter":"2020-Q2","reports":2149,"flag":"ICO: \"substantial drop in reporting in Q2 2020 which is likely a result of the first national UK coronavirus lockdown\"."},{"quarter":"2020-Q3","reports":2580},{"quarter":"2020-Q4","reports":2329},{"quarter":"2021-Q1","reports":2395},{"quarter":"2021-Q2","reports":2544},{"quarter":"2021-Q3","reports":2409},{"quarter":"2021-Q4","reports":2394},{"quarter":"2022-Q1","reports":2156},{"quarter":"2022-Q2","reports":2058},{"quarter":"2022-Q3","reports":2318},{"quarter":"2022-Q4","reports":2266},{"quarter":"2023-Q1","reports":2458},{"quarter":"2023-Q2","reports":2893},{"quarter":"2023-Q3","reports":2711},{"quarter":"2023-Q4","reports":3007},{"quarter":"2024-Q1","reports":2971},{"quarter":"2024-Q2","reports":3063},{"quarter":"2024-Q3","reports":3002},{"quarter":"2024-Q4","reports":3159},{"quarter":"2025-Q1","reports":3077},{"quarter":"2025-Q2","reports":3239},{"quarter":"2025-Q3","reports":3464},{"quarter":"2025-Q4","reports":3677,"flag":"Latest quarter, first release: incident type, sector and outcome coding is less complete than for earlier quarters (see revisions)."}],"highest_quarter":{"quarter":"2025-Q4","reports":3677},"caveats":["Counts are breach reports received, not breaches that occurred.","ICO: \"The data starts at Q2 2019 as incidents were recorded differently prior to this period.\" The file nonetheless contains 2019-Q1; it is shown but flagged.","ICO: \"substantial drop in reporting in Q2 2020 which is likely a result of the first national UK coronavirus lockdown\".","Latest quarter, first release: incident type, sector and outcome coding is less complete than for earlier quarters (see revisions)."]},"totals_by_year":{"title":"Reports per calendar year","values":[{"year":2019,"reports":12259,"quarters":4,"reports_q2_to_q4_only":8887,"flag":"Includes 2019-Q1, which the ICO says was recorded differently."},{"year":2020,"reports":9702,"quarters":4,"change_vs_previous_year_pct":-20.9,"flag":"ICO: \"substantial drop in reporting in Q2 2020 which is likely a result of the first national UK coronavirus lockdown\"."},{"year":2021,"reports":9742,"quarters":4,"change_vs_previous_year_pct":0.4},{"year":2022,"reports":8798,"quarters":4,"change_vs_previous_year_pct":-9.7},{"year":2023,"reports":11069,"quarters":4,"change_vs_previous_year_pct":25.8},{"year":2024,"reports":12195,"quarters":4,"change_vs_previous_year_pct":10.2},{"year":2025,"reports":13457,"quarters":4,"change_vs_previous_year_pct":10.3}],"highest_year":{"year":2025,"reports":13457},"lowest_year":{"year":2022,"reports":8798},"rose_every_year_since":2022,"caveats":["Calendar years of the date the report was received.","Year-on-year changes compare report counts only; they are not rates."]},"types_by_year":{"title":"Reports per incident type per calendar year","values":[{"incident_type":"Data emailed to incorrect recipient","catch_all":false,"by_year":{"2019":1377,"2020":1519,"2021":1693,"2022":1569,"2023":1746,"2024":2228,"2025":2459},"share_of_2025_reports_pct":18.3,"rank_2025":1},{"incident_type":"Other non-cyber incident","catch_all":true,"by_year":{"2019":3060,"2020":2249,"2021":1502,"2022":1123,"2023":1486,"2024":1685,"2025":1697},"share_of_2025_reports_pct":12.6,"rank_2025":2},{"incident_type":"Unauthorised access","catch_all":false,"by_year":{"2019":876,"2020":740,"2021":1127,"2022":1130,"2023":1304,"2024":1328,"2025":1597},"share_of_2025_reports_pct":11.9,"rank_2025":3},{"incident_type":"Phishing","catch_all":false,"by_year":{"2019":1103,"2020":1035,"2021":1045,"2022":716,"2023":924,"2024":1380,"2025":1526},"share_of_2025_reports_pct":11.3,"rank_2025":4},{"incident_type":"Failure to redact","catch_all":false,"by_year":{"2019":333,"2020":380,"2021":412,"2022":428,"2023":496,"2024":751,"2025":886},"share_of_2025_reports_pct":6.6,"rank_2025":5},{"incident_type":"Not Provided","catch_all":false,"by_year":{"2019":996,"2020":275,"2021":169,"2022":87,"2023":244,"2024":121,"2025":788},"share_of_2025_reports_pct":5.9,"rank_2025":6},{"incident_type":"Other cyber incident","catch_all":true,"by_year":{"2019":167,"2020":220,"2021":297,"2022":317,"2023":733,"2024":721,"2025":770},"share_of_2025_reports_pct":5.7,"rank_2025":7},{"incident_type":"Data posted or faxed to incorrect recipient","catch_all":false,"by_year":{"2019":1717,"2020":998,"2021":831,"2022":760,"2023":688,"2024":738,"2025":735},"share_of_2025_reports_pct":5.5,"rank_2025":8},{"incident_type":"Ransomware","catch_all":false,"by_year":{"2019":158,"2020":447,"2021":723,"2022":739,"2023":1253,"2024":752,"2025":617},"share_of_2025_reports_pct":4.6,"rank_2025":9},{"incident_type":"Loss/theft of paperwork or data left in insecure location","catch_all":false,"by_year":{"2019":1052,"2020":614,"2021":610,"2022":572,"2023":612,"2024":584,"2025":588},"share_of_2025_reports_pct":4.4,"rank_2025":10},{"incident_type":"Failure to use bcc","catch_all":false,"by_year":{"2019":332,"2020":362,"2021":279,"2022":246,"2023":323,"2024":416,"2025":434},"share_of_2025_reports_pct":3.2,"rank_2025":11},{"incident_type":"Hardware/software misconfiguration","catch_all":false,"by_year":{"2019":45,"2020":81,"2021":208,"2022":231,"2023":284,"2024":478,"2025":422},"share_of_2025_reports_pct":3.1,"rank_2025":12},{"incident_type":"Verbal disclosure of personal data","catch_all":false,"by_year":{"2019":268,"2020":253,"2021":291,"2022":308,"2023":287,"2024":339,"2025":348},"share_of_2025_reports_pct":2.6,"rank_2025":13},{"incident_type":"Data of wrong data subject shown in client portal","catch_all":false,"by_year":{"2019":121,"2020":92,"2021":103,"2022":148,"2023":163,"2024":208,"2025":228},"share_of_2025_reports_pct":1.7,"rank_2025":14},{"incident_type":"Loss/theft of device containing personal data","catch_all":false,"by_year":{"2019":428,"2020":220,"2021":168,"2022":172,"2023":189,"2024":186,"2025":154},"share_of_2025_reports_pct":1.1,"rank_2025":15},{"incident_type":"Malware","catch_all":false,"by_year":{"2019":104,"2020":114,"2021":116,"2022":103,"2023":171,"2024":122,"2025":102},"share_of_2025_reports_pct":0.8,"rank_2025":16},{"incident_type":"Brute Force","catch_all":false,"by_year":{"2019":36,"2020":65,"2021":79,"2022":63,"2023":91,"2024":88,"2025":45},"share_of_2025_reports_pct":0.3,"rank_2025":17},{"incident_type":"Incorrect disposal of paperwork","catch_all":false,"by_year":{"2019":55,"2020":21,"2021":36,"2022":36,"2023":45,"2024":55,"2025":38},"share_of_2025_reports_pct":0.3,"rank_2025":18},{"incident_type":"Alteration of personal data","catch_all":false,"by_year":{"2019":29,"2020":7,"2021":30,"2022":22,"2023":19,"2024":8,"2025":11},"share_of_2025_reports_pct":0.1,"rank_2025":19},{"incident_type":"Incorrect disposal of hardware","catch_all":false,"by_year":{"2019":2,"2020":6,"2021":8,"2022":10,"2023":3,"2024":4,"2025":9},"share_of_2025_reports_pct":0.1,"rank_2025":20},{"incident_type":"Denial of service","catch_all":false,"by_year":{"2019":0,"2020":4,"2021":13,"2022":10,"2023":5,"2024":3,"2025":3},"share_of_2025_reports_pct":0,"rank_2025":21},{"incident_type":"Cryptographic flaw","catch_all":false,"by_year":{"2019":0,"2020":0,"2021":2,"2022":8,"2023":3,"2024":0,"2025":0},"share_of_2025_reports_pct":0,"rank_2025":22}],"largest_type_2025":{"incident_type":"Data emailed to incorrect recipient","share_of_2025_reports_pct":18.3,"reports_2025":2459},"caveats":["The ICO assigns one incident type per report (the most significant).","\"Not Provided\" means no incident type was recorded; it is concentrated in the newest quarter (see revisions)."]},"cyber_share":{"title":"Cyber vs non-cyber share of reports over time","definitions":{"cyber_share_ico_pct":"ICO's own Cyber/Non Cyber coding, as published (cyber reports / all reports).","always_cyber_share_of_typed_pct":"Constant-definition series built for this study: reports whose incident type is always coded Cyber (Brute Force, Denial of service, Malware, Other cyber incident, Phishing, Ransomware) / reports with an incident type recorded (excludes \"Not Provided\"). It leaves out Unauthorised access, whose split between Cyber and Non Cyber changed over time, and never counts Hardware/software misconfiguration, which the row-level releases code Non Cyber."},"by_year":[{"year":2019,"reports":12259,"cyber_ico":2346,"non_cyber_ico":9913,"cyber_share_ico_pct":19.1,"non_cyber_share_ico_pct":80.9,"always_cyber_types":1568,"type_recorded":11263,"always_cyber_share_of_typed_pct":13.9},{"year":2020,"reports":9702,"cyber_ico":2190,"non_cyber_ico":7512,"cyber_share_ico_pct":22.6,"non_cyber_share_ico_pct":77.4,"always_cyber_types":1885,"type_recorded":9427,"always_cyber_share_of_typed_pct":20},{"year":2021,"reports":9742,"cyber_ico":2589,"non_cyber_ico":7153,"cyber_share_ico_pct":26.6,"non_cyber_share_ico_pct":73.4,"always_cyber_types":2273,"type_recorded":9573,"always_cyber_share_of_typed_pct":23.7},{"year":2022,"reports":8798,"cyber_ico":2156,"non_cyber_ico":6642,"cyber_share_ico_pct":24.5,"non_cyber_share_ico_pct":75.5,"always_cyber_types":1948,"type_recorded":8711,"always_cyber_share_of_typed_pct":22.4},{"year":2023,"reports":11069,"cyber_ico":3319,"non_cyber_ico":7750,"cyber_share_ico_pct":30,"non_cyber_share_ico_pct":70,"always_cyber_types":3177,"type_recorded":10825,"always_cyber_share_of_typed_pct":29.3},{"year":2024,"reports":12195,"cyber_ico":3116,"non_cyber_ico":9079,"cyber_share_ico_pct":25.6,"non_cyber_share_ico_pct":74.4,"always_cyber_types":3066,"type_recorded":12074,"always_cyber_share_of_typed_pct":25.4},{"year":2025,"reports":13457,"cyber_ico":3153,"non_cyber_ico":10304,"cyber_share_ico_pct":23.4,"non_cyber_share_ico_pct":76.6,"always_cyber_types":3063,"type_recorded":12669,"always_cyber_share_of_typed_pct":24.2}],"by_quarter":[{"quarter":"2019-Q1","reports":3372,"cyber_ico":697,"non_cyber_ico":2675,"cyber_share_ico_pct":20.7,"non_cyber_share_ico_pct":79.3,"always_cyber_types":318,"type_recorded":2986,"always_cyber_share_of_typed_pct":10.6},{"quarter":"2019-Q2","reports":3077,"cyber_ico":628,"non_cyber_ico":2449,"cyber_share_ico_pct":20.4,"non_cyber_share_ico_pct":79.6,"always_cyber_types":432,"type_recorded":2685,"always_cyber_share_of_typed_pct":16.1},{"quarter":"2019-Q3","reports":3002,"cyber_ico":545,"non_cyber_ico":2457,"cyber_share_ico_pct":18.2,"non_cyber_share_ico_pct":81.8,"always_cyber_types":421,"type_recorded":2895,"always_cyber_share_of_typed_pct":14.5},{"quarter":"2019-Q4","reports":2808,"cyber_ico":476,"non_cyber_ico":2332,"cyber_share_ico_pct":17,"non_cyber_share_ico_pct":83,"always_cyber_types":397,"type_recorded":2697,"always_cyber_share_of_typed_pct":14.7},{"quarter":"2020-Q1","reports":2644,"cyber_ico":516,"non_cyber_ico":2128,"cyber_share_ico_pct":19.5,"non_cyber_share_ico_pct":80.5,"always_cyber_types":445,"type_recorded":2579,"always_cyber_share_of_typed_pct":17.3},{"quarter":"2020-Q2","reports":2149,"cyber_ico":534,"non_cyber_ico":1615,"cyber_share_ico_pct":24.8,"non_cyber_share_ico_pct":75.2,"always_cyber_types":455,"type_recorded":2090,"always_cyber_share_of_typed_pct":21.8},{"quarter":"2020-Q3","reports":2580,"cyber_ico":614,"non_cyber_ico":1966,"cyber_share_ico_pct":23.8,"non_cyber_share_ico_pct":76.2,"always_cyber_types":530,"type_recorded":2491,"always_cyber_share_of_typed_pct":21.3},{"quarter":"2020-Q4","reports":2329,"cyber_ico":526,"non_cyber_ico":1803,"cyber_share_ico_pct":22.6,"non_cyber_share_ico_pct":77.4,"always_cyber_types":455,"type_recorded":2267,"always_cyber_share_of_typed_pct":20.1},{"quarter":"2021-Q1","reports":2395,"cyber_ico":622,"non_cyber_ico":1773,"cyber_share_ico_pct":26,"non_cyber_share_ico_pct":74,"always_cyber_types":555,"type_recorded":2337,"always_cyber_share_of_typed_pct":23.7},{"quarter":"2021-Q2","reports":2544,"cyber_ico":724,"non_cyber_ico":1820,"cyber_share_ico_pct":28.5,"non_cyber_share_ico_pct":71.5,"always_cyber_types":587,"type_recorded":2497,"always_cyber_share_of_typed_pct":23.5},{"quarter":"2021-Q3","reports":2409,"cyber_ico":671,"non_cyber_ico":1738,"cyber_share_ico_pct":27.9,"non_cyber_share_ico_pct":72.1,"always_cyber_types":608,"type_recorded":2374,"always_cyber_share_of_typed_pct":25.6},{"quarter":"2021-Q4","reports":2394,"cyber_ico":572,"non_cyber_ico":1822,"cyber_share_ico_pct":23.9,"non_cyber_share_ico_pct":76.1,"always_cyber_types":523,"type_recorded":2365,"always_cyber_share_of_typed_pct":22.1},{"quarter":"2022-Q1","reports":2156,"cyber_ico":480,"non_cyber_ico":1676,"cyber_share_ico_pct":22.3,"non_cyber_share_ico_pct":77.7,"always_cyber_types":421,"type_recorded":2147,"always_cyber_share_of_typed_pct":19.6},{"quarter":"2022-Q2","reports":2058,"cyber_ico":417,"non_cyber_ico":1641,"cyber_share_ico_pct":20.3,"non_cyber_share_ico_pct":79.7,"always_cyber_types":355,"type_recorded":2034,"always_cyber_share_of_typed_pct":17.5},{"quarter":"2022-Q3","reports":2318,"cyber_ico":682,"non_cyber_ico":1636,"cyber_share_ico_pct":29.4,"non_cyber_share_ico_pct":70.6,"always_cyber_types":629,"type_recorded":2284,"always_cyber_share_of_typed_pct":27.5},{"quarter":"2022-Q4","reports":2266,"cyber_ico":577,"non_cyber_ico":1689,"cyber_share_ico_pct":25.5,"non_cyber_share_ico_pct":74.5,"always_cyber_types":543,"type_recorded":2246,"always_cyber_share_of_typed_pct":24.2},{"quarter":"2023-Q1","reports":2458,"cyber_ico":607,"non_cyber_ico":1851,"cyber_share_ico_pct":24.7,"non_cyber_share_ico_pct":75.3,"always_cyber_types":578,"type_recorded":2414,"always_cyber_share_of_typed_pct":23.9},{"quarter":"2023-Q2","reports":2893,"cyber_ico":1127,"non_cyber_ico":1766,"cyber_share_ico_pct":39,"non_cyber_share_ico_pct":61,"always_cyber_types":1066,"type_recorded":2795,"always_cyber_share_of_typed_pct":38.1},{"quarter":"2023-Q3","reports":2711,"cyber_ico":689,"non_cyber_ico":2022,"cyber_share_ico_pct":25.4,"non_cyber_share_ico_pct":74.6,"always_cyber_types":662,"type_recorded":2658,"always_cyber_share_of_typed_pct":24.9},{"quarter":"2023-Q4","reports":3007,"cyber_ico":896,"non_cyber_ico":2111,"cyber_share_ico_pct":29.8,"non_cyber_share_ico_pct":70.2,"always_cyber_types":871,"type_recorded":2958,"always_cyber_share_of_typed_pct":29.4},{"quarter":"2024-Q1","reports":2971,"cyber_ico":807,"non_cyber_ico":2164,"cyber_share_ico_pct":27.2,"non_cyber_share_ico_pct":72.8,"always_cyber_types":791,"type_recorded":2948,"always_cyber_share_of_typed_pct":26.8},{"quarter":"2024-Q2","reports":3063,"cyber_ico":904,"non_cyber_ico":2159,"cyber_share_ico_pct":29.5,"non_cyber_share_ico_pct":70.5,"always_cyber_types":887,"type_recorded":3035,"always_cyber_share_of_typed_pct":29.2},{"quarter":"2024-Q3","reports":3002,"cyber_ico":715,"non_cyber_ico":2287,"cyber_share_ico_pct":23.8,"non_cyber_share_ico_pct":76.2,"always_cyber_types":709,"type_recorded":2969,"always_cyber_share_of_typed_pct":23.9},{"quarter":"2024-Q4","reports":3159,"cyber_ico":690,"non_cyber_ico":2469,"cyber_share_ico_pct":21.8,"non_cyber_share_ico_pct":78.2,"always_cyber_types":679,"type_recorded":3122,"always_cyber_share_of_typed_pct":21.7},{"quarter":"2025-Q1","reports":3077,"cyber_ico":770,"non_cyber_ico":2307,"cyber_share_ico_pct":25,"non_cyber_share_ico_pct":75,"always_cyber_types":760,"type_recorded":3058,"always_cyber_share_of_typed_pct":24.9},{"quarter":"2025-Q2","reports":3239,"cyber_ico":772,"non_cyber_ico":2467,"cyber_share_ico_pct":23.8,"non_cyber_share_ico_pct":76.2,"always_cyber_types":734,"type_recorded":3216,"always_cyber_share_of_typed_pct":22.8},{"quarter":"2025-Q3","reports":3464,"cyber_ico":755,"non_cyber_ico":2709,"cyber_share_ico_pct":21.8,"non_cyber_share_ico_pct":78.2,"always_cyber_types":730,"type_recorded":3367,"always_cyber_share_of_typed_pct":21.7},{"quarter":"2025-Q4","reports":3677,"cyber_ico":856,"non_cyber_ico":2821,"cyber_share_ico_pct":23.3,"non_cyber_share_ico_pct":76.7,"always_cyber_types":839,"type_recorded":3028,"always_cyber_share_of_typed_pct":27.7}],"caveats":["ICO: \"The way we categorise incidents as cyber or non-cyber within the dashboard is currently under review ... caution should be taken when drawing conclusions from the split of incident category.\"","The share of Unauthorised access reports the ICO codes Cyber changed over time (see series_breaks and unauthorised_access_coding), so the ICO cyber share is not a constant-definition measure.","The ICO codes every report with no incident type (\"Not Provided\", 2,680 reports in the file) as Non Cyber, so the 649 uncoded reports in 2025-Q4 count as non-cyber in the ICO share. The effect is small: the ICO-coded cyber share is 23.5% for 2025 Q1-Q3 against 23.4% for the full year."],"q1_q3_2025":{"year":"2025 Q1-Q3","reports":9780,"cyber_ico":2297,"non_cyber_ico":7483,"cyber_share_ico_pct":23.5,"non_cyber_share_ico_pct":76.5,"always_cyber_types":2224,"type_recorded":9641,"always_cyber_share_of_typed_pct":23.1},"not_provided_coding":{"not_provided_reports_all_quarters":2680,"coded_non_cyber":2680,"latest_quarter":"2025-Q4","latest_quarter_not_provided":649},"highest_year_ico":{"year":2023,"cyber_share_ico_pct":30},"reading":"ICO-coded cyber share: 19.1% (2019), 30.0% (2023), 23.4% (2025). Constant-definition share: 13.9%, 29.3%, 24.2%. The ICO series starts higher in 2019 partly because 778 Unauthorised access reports were coded Cyber that year; on the constant definition the rise to 2023 is larger and the fall to 2025 smaller."},"unauthorised_access_coding":{"title":"How \"Unauthorised access\" reports were split between Cyber and Non Cyber","values":[{"year":2019,"coded_cyber":778,"coded_non_cyber":98,"cyber_coded_share_pct":88.8},{"year":2020,"coded_cyber":305,"coded_non_cyber":435,"cyber_coded_share_pct":41.2},{"year":2021,"coded_cyber":316,"coded_non_cyber":811,"cyber_coded_share_pct":28},{"year":2022,"coded_cyber":208,"coded_non_cyber":922,"cyber_coded_share_pct":18.4},{"year":2023,"coded_cyber":142,"coded_non_cyber":1162,"cyber_coded_share_pct":10.9},{"year":2024,"coded_cyber":50,"coded_non_cyber":1278,"cyber_coded_share_pct":3.8},{"year":2025,"coded_cyber":90,"coded_non_cyber":1507,"cyber_coded_share_pct":5.6}],"by_quarter":[{"quarter":"2019-Q1","coded_cyber":379,"coded_non_cyber":0,"cyber_coded_share_pct":100},{"quarter":"2019-Q2","coded_cyber":196,"coded_non_cyber":0,"cyber_coded_share_pct":100},{"quarter":"2019-Q3","coded_cyber":124,"coded_non_cyber":18,"cyber_coded_share_pct":87.3},{"quarter":"2019-Q4","coded_cyber":79,"coded_non_cyber":80,"cyber_coded_share_pct":49.7},{"quarter":"2020-Q1","coded_cyber":71,"coded_non_cyber":114,"cyber_coded_share_pct":38.4},{"quarter":"2020-Q2","coded_cyber":79,"coded_non_cyber":73,"cyber_coded_share_pct":52},{"quarter":"2020-Q3","coded_cyber":84,"coded_non_cyber":106,"cyber_coded_share_pct":44.2},{"quarter":"2020-Q4","coded_cyber":71,"coded_non_cyber":142,"cyber_coded_share_pct":33.3},{"quarter":"2021-Q1","coded_cyber":67,"coded_non_cyber":162,"cyber_coded_share_pct":29.3},{"quarter":"2021-Q2","coded_cyber":137,"coded_non_cyber":174,"cyber_coded_share_pct":44.1},{"quarter":"2021-Q3","coded_cyber":63,"coded_non_cyber":209,"cyber_coded_share_pct":23.2},{"quarter":"2021-Q4","coded_cyber":49,"coded_non_cyber":266,"cyber_coded_share_pct":15.6},{"quarter":"2022-Q1","coded_cyber":59,"coded_non_cyber":219,"cyber_coded_share_pct":21.2},{"quarter":"2022-Q2","coded_cyber":62,"coded_non_cyber":230,"cyber_coded_share_pct":21.2},{"quarter":"2022-Q3","coded_cyber":53,"coded_non_cyber":224,"cyber_coded_share_pct":19.1},{"quarter":"2022-Q4","coded_cyber":34,"coded_non_cyber":249,"cyber_coded_share_pct":12},{"quarter":"2023-Q1","coded_cyber":29,"coded_non_cyber":277,"cyber_coded_share_pct":9.5},{"quarter":"2023-Q2","coded_cyber":61,"coded_non_cyber":259,"cyber_coded_share_pct":19.1},{"quarter":"2023-Q3","coded_cyber":27,"coded_non_cyber":317,"cyber_coded_share_pct":7.8},{"quarter":"2023-Q4","coded_cyber":25,"coded_non_cyber":309,"cyber_coded_share_pct":7.5},{"quarter":"2024-Q1","coded_cyber":16,"coded_non_cyber":338,"cyber_coded_share_pct":4.5},{"quarter":"2024-Q2","coded_cyber":17,"coded_non_cyber":333,"cyber_coded_share_pct":4.9},{"quarter":"2024-Q3","coded_cyber":6,"coded_non_cyber":301,"cyber_coded_share_pct":2},{"quarter":"2024-Q4","coded_cyber":11,"coded_non_cyber":306,"cyber_coded_share_pct":3.5},{"quarter":"2025-Q1","coded_cyber":10,"coded_non_cyber":322,"cyber_coded_share_pct":3},{"quarter":"2025-Q2","coded_cyber":38,"coded_non_cyber":418,"cyber_coded_share_pct":8.3},{"quarter":"2025-Q3","coded_cyber":25,"coded_non_cyber":411,"cyber_coded_share_pct":5.7},{"quarter":"2025-Q4","coded_cyber":17,"coded_non_cyber":356,"cyber_coded_share_pct":4.6}],"quarters_coded_all_cyber":["2019-Q1","2019-Q2"],"cyber_minority_every_year_from":2020,"lowest_year_from_2020":{"year":2024,"cyber_coded_share_pct":3.8},"ico_definition":"ICO glossary: \"This incident type is used both in instances where an individual has unlawfully accessed or disclosed information and where a third party has forcibly accessed a system.\"","reading":"The ICO coded Unauthorised access as Cyber in every 2019-Q1 and 2019-Q2 report (88.8% across 2019) but in a minority each year from 2020 (41.2% in 2020, falling to 3.8% in 2024; 5.6% in 2025). The data cannot show whether this reflects a coding change or a change in the kind of unauthorised access reported. Either way, it changes the ICO cyber/non-cyber split over time, which is why this study also shows a constant-definition cyber series that leaves this type out."},"ransomware_over_time":{"title":"Ransomware reports per quarter and per year","by_quarter":[{"quarter":"2019-Q1","ransomware":44,"share_of_all_pct":1.3,"share_of_cyber_ico_pct":6.3},{"quarter":"2019-Q2","ransomware":43,"share_of_all_pct":1.4,"share_of_cyber_ico_pct":6.8},{"quarter":"2019-Q3","ransomware":41,"share_of_all_pct":1.4,"share_of_cyber_ico_pct":7.5},{"quarter":"2019-Q4","ransomware":30,"share_of_all_pct":1.1,"share_of_cyber_ico_pct":6.3},{"quarter":"2020-Q1","ransomware":61,"share_of_all_pct":2.3,"share_of_cyber_ico_pct":11.8},{"quarter":"2020-Q2","ransomware":87,"share_of_all_pct":4,"share_of_cyber_ico_pct":16.3},{"quarter":"2020-Q3","ransomware":157,"share_of_all_pct":6.1,"share_of_cyber_ico_pct":25.6},{"quarter":"2020-Q4","ransomware":142,"share_of_all_pct":6.1,"share_of_cyber_ico_pct":27},{"quarter":"2021-Q1","ransomware":157,"share_of_all_pct":6.6,"share_of_cyber_ico_pct":25.2},{"quarter":"2021-Q2","ransomware":147,"share_of_all_pct":5.8,"share_of_cyber_ico_pct":20.3},{"quarter":"2021-Q3","ransomware":230,"share_of_all_pct":9.5,"share_of_cyber_ico_pct":34.3},{"quarter":"2021-Q4","ransomware":189,"share_of_all_pct":7.9,"share_of_cyber_ico_pct":33},{"quarter":"2022-Q1","ransomware":144,"share_of_all_pct":6.7,"share_of_cyber_ico_pct":30},{"quarter":"2022-Q2","ransomware":145,"share_of_all_pct":7,"share_of_cyber_ico_pct":34.8},{"quarter":"2022-Q3","ransomware":318,"share_of_all_pct":13.7,"share_of_cyber_ico_pct":46.6},{"quarter":"2022-Q4","ransomware":132,"share_of_all_pct":5.8,"share_of_cyber_ico_pct":22.9},{"quarter":"2023-Q1","ransomware":173,"share_of_all_pct":7,"share_of_cyber_ico_pct":28.5},{"quarter":"2023-Q2","ransomware":511,"share_of_all_pct":17.7,"share_of_cyber_ico_pct":45.3},{"quarter":"2023-Q3","ransomware":211,"share_of_all_pct":7.8,"share_of_cyber_ico_pct":30.6},{"quarter":"2023-Q4","ransomware":358,"share_of_all_pct":11.9,"share_of_cyber_ico_pct":40},{"quarter":"2024-Q1","ransomware":223,"share_of_all_pct":7.5,"share_of_cyber_ico_pct":27.6},{"quarter":"2024-Q2","ransomware":219,"share_of_all_pct":7.1,"share_of_cyber_ico_pct":24.2},{"quarter":"2024-Q3","ransomware":161,"share_of_all_pct":5.4,"share_of_cyber_ico_pct":22.5},{"quarter":"2024-Q4","ransomware":149,"share_of_all_pct":4.7,"share_of_cyber_ico_pct":21.6},{"quarter":"2025-Q1","ransomware":165,"share_of_all_pct":5.4,"share_of_cyber_ico_pct":21.4},{"quarter":"2025-Q2","ransomware":165,"share_of_all_pct":5.1,"share_of_cyber_ico_pct":21.4},{"quarter":"2025-Q3","ransomware":139,"share_of_all_pct":4,"share_of_cyber_ico_pct":18.4},{"quarter":"2025-Q4","ransomware":148,"share_of_all_pct":4,"share_of_cyber_ico_pct":17.3}],"by_year":[{"year":2019,"ransomware":158,"share_of_all_pct":1.3,"share_of_cyber_ico_pct":6.7,"ransomware_q1_q3":128},{"year":2020,"ransomware":447,"share_of_all_pct":4.6,"share_of_cyber_ico_pct":20.4,"ransomware_q1_q3":305},{"year":2021,"ransomware":723,"share_of_all_pct":7.4,"share_of_cyber_ico_pct":27.9,"ransomware_q1_q3":534},{"year":2022,"ransomware":739,"share_of_all_pct":8.4,"share_of_cyber_ico_pct":34.3,"ransomware_q1_q3":607},{"year":2023,"ransomware":1253,"share_of_all_pct":11.3,"share_of_cyber_ico_pct":37.8,"ransomware_q1_q3":895},{"year":2024,"ransomware":752,"share_of_all_pct":6.2,"share_of_cyber_ico_pct":24.1,"ransomware_q1_q3":603},{"year":2025,"ransomware":617,"share_of_all_pct":4.6,"share_of_cyber_ico_pct":19.6,"ransomware_q1_q3":469}],"peak_quarter":{"quarter":"2023-Q2","ransomware":511,"largest_sector":"Finance, insurance and credit","largest_sector_ransomware":201},"peak_year":{"year":2023,"ransomware":1253},"caveats":["The ICO assigns one incident type per report (the most significant); a ransomware attack recorded under another type is not counted here.","The data carries no organisation identifier, so it cannot show whether several reports stem from one underlying incident (for example at a shared supplier).","2023-Q2, the peak quarter (511 ransomware reports), includes 201 from Finance, insurance and credit. The data cannot show whether several of these stem from one underlying incident, and no incident is named here.","ransomware_q1_q3 counts only the first three quarters of each year, a check that leaves out the provisional 2025-Q4."]},"ransomware_by_sector":{"title":"Ransomware reports by sector: count, and share of each sector's own reports","min_n_for_share_ranking":100,"periods":[{"period":"2019-2025 (all quarters in file)","quarters":["2019-Q1","2025-Q4"],"ransomware_total":4689,"ransomware_with_unknown_or_unassigned_sector":3,"top_by_count":["Retail and manufacture","Finance, insurance and credit","Education and childcare","Health","Online Technology and Telecoms","Local government","General business","Transport and leisure","Legal","Land or property services"],"top_by_share_of_own_reports":["Retail and manufacture","Online Technology and Telecoms","Marketing","Finance, insurance and credit","Media","Transport and leisure","Utilities","Membership association","General business","Land or property services"],"sectors":[{"sector":"Retail and manufacture","reports":7293,"ransomware":1168,"share_of_sector_reports_pct":16,"share_of_all_ransomware_pct":24.9,"meets_min_n":true},{"sector":"Finance, insurance and credit","reports":7186,"ransomware":807,"share_of_sector_reports_pct":11.2,"share_of_all_ransomware_pct":17.2,"meets_min_n":true},{"sector":"Education and childcare","reports":10729,"ransomware":499,"share_of_sector_reports_pct":4.7,"share_of_all_ransomware_pct":10.6,"meets_min_n":true},{"sector":"Health","reports":14308,"ransomware":316,"share_of_sector_reports_pct":2.2,"share_of_all_ransomware_pct":6.7,"meets_min_n":true},{"sector":"Online Technology and Telecoms","reports":1905,"ransomware":260,"share_of_sector_reports_pct":13.6,"share_of_all_ransomware_pct":5.5,"meets_min_n":true},{"sector":"Local government","reports":6903,"ransomware":242,"share_of_sector_reports_pct":3.5,"share_of_all_ransomware_pct":5.2,"meets_min_n":true},{"sector":"General business","reports":3715,"ransomware":232,"share_of_sector_reports_pct":6.2,"share_of_all_ransomware_pct":4.9,"meets_min_n":true},{"sector":"Transport and leisure","reports":2570,"ransomware":224,"share_of_sector_reports_pct":8.7,"share_of_all_ransomware_pct":4.8,"meets_min_n":true},{"sector":"Legal","reports":5616,"ransomware":223,"share_of_sector_reports_pct":4,"share_of_all_ransomware_pct":4.8,"meets_min_n":true},{"sector":"Land or property services","reports":3618,"ransomware":217,"share_of_sector_reports_pct":6,"share_of_all_ransomware_pct":4.6,"meets_min_n":true},{"sector":"Charitable and voluntary","reports":4654,"ransomware":216,"share_of_sector_reports_pct":4.6,"share_of_all_ransomware_pct":4.6,"meets_min_n":true},{"sector":"Membership association","reports":1078,"ransomware":70,"share_of_sector_reports_pct":6.5,"share_of_all_ransomware_pct":1.5,"meets_min_n":true},{"sector":"Utilities","reports":749,"ransomware":56,"share_of_sector_reports_pct":7.5,"share_of_all_ransomware_pct":1.2,"meets_min_n":true},{"sector":"Social care","reports":2065,"ransomware":40,"share_of_sector_reports_pct":1.9,"share_of_all_ransomware_pct":0.9,"meets_min_n":true},{"sector":"Marketing","reports":280,"ransomware":34,"share_of_sector_reports_pct":12.1,"share_of_all_ransomware_pct":0.7,"meets_min_n":true},{"sector":"Central Government","reports":2132,"ransomware":24,"share_of_sector_reports_pct":1.1,"share_of_all_ransomware_pct":0.5,"meets_min_n":true},{"sector":"Media","reports":215,"ransomware":20,"share_of_sector_reports_pct":9.3,"share_of_all_ransomware_pct":0.4,"meets_min_n":true},{"sector":"Justice","reports":1317,"ransomware":15,"share_of_sector_reports_pct":1.1,"share_of_all_ransomware_pct":0.3,"meets_min_n":true},{"sector":"Religious","reports":293,"ransomware":14,"share_of_sector_reports_pct":4.8,"share_of_all_ransomware_pct":0.3,"meets_min_n":true},{"sector":"Regulators","reports":303,"ransomware":6,"share_of_sector_reports_pct":2,"share_of_all_ransomware_pct":0.1,"meets_min_n":true},{"sector":"Political","reports":190,"ransomware":3,"share_of_sector_reports_pct":1.6,"share_of_all_ransomware_pct":0.1,"meets_min_n":true}]},{"period":"2024-2025","quarters":["2024-Q1","2025-Q4"],"ransomware_total":1369,"ransomware_with_unknown_or_unassigned_sector":3,"top_by_count":["Retail and manufacture","Finance, insurance and credit","Education and childcare","Health","Online Technology and Telecoms","Land or property services","Legal","Transport and leisure","Local government","Charitable and voluntary"],"top_by_share_of_own_reports":["Retail and manufacture","Online Technology and Telecoms","Marketing","General business","Finance, insurance and credit","Transport and leisure","Land or property services","Membership association","Utilities","Legal"],"sectors":[{"sector":"Retail and manufacture","reports":2831,"ransomware":457,"share_of_sector_reports_pct":16.1,"share_of_all_ransomware_pct":33.4,"meets_min_n":true},{"sector":"Finance, insurance and credit","reports":2043,"ransomware":159,"share_of_sector_reports_pct":7.8,"share_of_all_ransomware_pct":11.6,"meets_min_n":true},{"sector":"Education and childcare","reports":3542,"ransomware":126,"share_of_sector_reports_pct":3.6,"share_of_all_ransomware_pct":9.2,"meets_min_n":true},{"sector":"Health","reports":4913,"ransomware":100,"share_of_sector_reports_pct":2,"share_of_all_ransomware_pct":7.3,"meets_min_n":true},{"sector":"Online Technology and Telecoms","reports":648,"ransomware":95,"share_of_sector_reports_pct":14.7,"share_of_all_ransomware_pct":6.9,"meets_min_n":true},{"sector":"Land or property services","reports":1354,"ransomware":73,"share_of_sector_reports_pct":5.4,"share_of_all_ransomware_pct":5.3,"meets_min_n":true},{"sector":"Legal","reports":1757,"ransomware":64,"share_of_sector_reports_pct":3.6,"share_of_all_ransomware_pct":4.7,"meets_min_n":true},{"sector":"Transport and leisure","reports":973,"ransomware":61,"share_of_sector_reports_pct":6.3,"share_of_all_ransomware_pct":4.5,"meets_min_n":true},{"sector":"Local government","reports":2228,"ransomware":60,"share_of_sector_reports_pct":2.7,"share_of_all_ransomware_pct":4.4,"meets_min_n":true},{"sector":"Charitable and voluntary","reports":1825,"ransomware":59,"share_of_sector_reports_pct":3.2,"share_of_all_ransomware_pct":4.3,"meets_min_n":true},{"sector":"General business","reports":565,"ransomware":45,"share_of_sector_reports_pct":8,"share_of_all_ransomware_pct":3.3,"meets_min_n":true},{"sector":"Membership association","reports":396,"ransomware":20,"share_of_sector_reports_pct":5.1,"share_of_all_ransomware_pct":1.5,"meets_min_n":true},{"sector":"Marketing","reports":138,"ransomware":14,"share_of_sector_reports_pct":10.1,"share_of_all_ransomware_pct":1,"meets_min_n":true},{"sector":"Utilities","reports":248,"ransomware":11,"share_of_sector_reports_pct":4.4,"share_of_all_ransomware_pct":0.8,"meets_min_n":true},{"sector":"Social care","reports":877,"ransomware":7,"share_of_sector_reports_pct":0.8,"share_of_all_ransomware_pct":0.5,"meets_min_n":true},{"sector":"Central Government","reports":427,"ransomware":4,"share_of_sector_reports_pct":0.9,"share_of_all_ransomware_pct":0.3,"meets_min_n":true},{"sector":"Media","reports":52,"ransomware":4,"share_of_sector_reports_pct":7.7,"share_of_all_ransomware_pct":0.3,"meets_min_n":false},{"sector":"Justice","reports":456,"ransomware":3,"share_of_sector_reports_pct":0.7,"share_of_all_ransomware_pct":0.2,"meets_min_n":true},{"sector":"Regulators","reports":104,"ransomware":2,"share_of_sector_reports_pct":1.9,"share_of_all_ransomware_pct":0.1,"meets_min_n":true},{"sector":"Political","reports":72,"ransomware":1,"share_of_sector_reports_pct":1.4,"share_of_all_ransomware_pct":0.1,"meets_min_n":false},{"sector":"Religious","reports":105,"ransomware":1,"share_of_sector_reports_pct":1,"share_of_all_ransomware_pct":0.1,"meets_min_n":true}]},{"period":"2025","quarters":["2025-Q1","2025-Q4"],"ransomware_total":617,"ransomware_with_unknown_or_unassigned_sector":3,"top_by_count":["Retail and manufacture","Finance, insurance and credit","Education and childcare","Legal","Land or property services","Online Technology and Telecoms","Transport and leisure","Health","General business","Charitable and voluntary"],"top_by_share_of_own_reports":["Retail and manufacture","Online Technology and Telecoms","Utilities","Finance, insurance and credit","General business","Transport and leisure","Land or property services","Legal","Membership association","Education and childcare"],"sectors":[{"sector":"Retail and manufacture","reports":1497,"ransomware":227,"share_of_sector_reports_pct":15.2,"share_of_all_ransomware_pct":36.8,"meets_min_n":true},{"sector":"Finance, insurance and credit","reports":1069,"ransomware":76,"share_of_sector_reports_pct":7.1,"share_of_all_ransomware_pct":12.3,"meets_min_n":true},{"sector":"Education and childcare","reports":1830,"ransomware":44,"share_of_sector_reports_pct":2.4,"share_of_all_ransomware_pct":7.1,"meets_min_n":true},{"sector":"Legal","reports":962,"ransomware":42,"share_of_sector_reports_pct":4.4,"share_of_all_ransomware_pct":6.8,"meets_min_n":true},{"sector":"Land or property services","reports":768,"ransomware":39,"share_of_sector_reports_pct":5.1,"share_of_all_ransomware_pct":6.3,"meets_min_n":true},{"sector":"Online Technology and Telecoms","reports":338,"ransomware":39,"share_of_sector_reports_pct":11.5,"share_of_all_ransomware_pct":6.3,"meets_min_n":true},{"sector":"Transport and leisure","reports":535,"ransomware":32,"share_of_sector_reports_pct":6,"share_of_all_ransomware_pct":5.2,"meets_min_n":true},{"sector":"Health","reports":2471,"ransomware":22,"share_of_sector_reports_pct":0.9,"share_of_all_ransomware_pct":3.6,"meets_min_n":true},{"sector":"General business","reports":292,"ransomware":20,"share_of_sector_reports_pct":6.8,"share_of_all_ransomware_pct":3.2,"meets_min_n":true},{"sector":"Charitable and voluntary","reports":979,"ransomware":19,"share_of_sector_reports_pct":1.9,"share_of_all_ransomware_pct":3.1,"meets_min_n":true},{"sector":"Local government","reports":1080,"ransomware":19,"share_of_sector_reports_pct":1.8,"share_of_all_ransomware_pct":3.1,"meets_min_n":true},{"sector":"Utilities","reports":135,"ransomware":10,"share_of_sector_reports_pct":7.4,"share_of_all_ransomware_pct":1.6,"meets_min_n":true},{"sector":"Marketing","reports":69,"ransomware":7,"share_of_sector_reports_pct":10.1,"share_of_all_ransomware_pct":1.1,"meets_min_n":false},{"sector":"Membership association","reports":201,"ransomware":6,"share_of_sector_reports_pct":3,"share_of_all_ransomware_pct":1,"meets_min_n":true},{"sector":"Media","reports":32,"ransomware":4,"share_of_sector_reports_pct":12.5,"share_of_all_ransomware_pct":0.6,"meets_min_n":false},{"sector":"Justice","reports":257,"ransomware":3,"share_of_sector_reports_pct":1.2,"share_of_all_ransomware_pct":0.5,"meets_min_n":true},{"sector":"Central Government","reports":208,"ransomware":2,"share_of_sector_reports_pct":1,"share_of_all_ransomware_pct":0.3,"meets_min_n":true},{"sector":"Social care","reports":479,"ransomware":2,"share_of_sector_reports_pct":0.4,"share_of_all_ransomware_pct":0.3,"meets_min_n":true},{"sector":"Regulators","reports":59,"ransomware":1,"share_of_sector_reports_pct":1.7,"share_of_all_ransomware_pct":0.2,"meets_min_n":false},{"sector":"Political","reports":41,"ransomware":0,"share_of_sector_reports_pct":0,"share_of_all_ransomware_pct":0,"meets_min_n":false},{"sector":"Religious","reports":57,"ransomware":0,"share_of_sector_reports_pct":0,"share_of_all_ransomware_pct":0,"meets_min_n":false}]}],"caveats":["\"Share of own reports\" is ransomware reports / all breach reports from that sector. It is not a rate per organisation: the data has no count of organisations per sector.","ICO: \"the sector is allocated by the ICO and is assigned as a best fit\"; the glossary adds that sectors \"are not defined in detail as there are a number of inconsistencies in how these are used, particularly within the historic data.\"","Sectors with fewer than 100 reports in the period are listed but not ranked by share. \"Unknown\"/\"Unassigned\" sectors are excluded from rankings.","Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.","Rankings by share use the unrounded ratio, so sectors whose shares round to the same value are still ordered correctly."]},"fastest_growing_types":{"title":"Fastest-growing incident types (named types only; catch-all \"Other\" types flagged)","min_base":100,"windows":[{"window":"2021 to 2025","base_quarters":["2021-Q1","2021-Q4"],"end_quarters":["2025-Q1","2025-Q4"],"note":"Four-year window. Starts after the 2020 lockdown quarter and the 2019 recording change.","all_reports":{"base":9742,"end":13457,"change_pct":38.1},"not_provided":{"base":169,"end":788},"fastest_growing_named_types":["Data of wrong data subject shown in client portal","Failure to redact","Hardware/software misconfiguration","Failure to use bcc","Phishing"],"falling_named_types":["Loss/theft of paperwork or data left in insecure location","Loss/theft of device containing personal data","Data posted or faxed to incorrect recipient","Malware","Ransomware"],"types":[{"incident_type":"Other cyber incident","base":297,"end":770,"change":473,"change_pct":159.3,"meets_min_base":true,"catch_all":true},{"incident_type":"Data of wrong data subject shown in client portal","base":103,"end":228,"change":125,"change_pct":121.4,"meets_min_base":true,"catch_all":false},{"incident_type":"Failure to redact","base":412,"end":886,"change":474,"change_pct":115,"meets_min_base":true,"catch_all":false},{"incident_type":"Hardware/software misconfiguration","base":208,"end":422,"change":214,"change_pct":102.9,"meets_min_base":true,"catch_all":false,"note":"Coded Non Cyber in every row-level release; listed under cyber in the FY2021/22 aggregate tables."},{"incident_type":"Failure to use bcc","base":279,"end":434,"change":155,"change_pct":55.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Phishing","base":1045,"end":1526,"change":481,"change_pct":46,"meets_min_base":true,"catch_all":false},{"incident_type":"Data emailed to incorrect recipient","base":1693,"end":2459,"change":766,"change_pct":45.2,"meets_min_base":true,"catch_all":false},{"incident_type":"Unauthorised access","base":1127,"end":1597,"change":470,"change_pct":41.7,"meets_min_base":true,"catch_all":false,"note":"Both ICO categories combined (the Cyber/Non Cyber split changed over time; see unauthorised_access_coding)."},{"incident_type":"Verbal disclosure of personal data","base":291,"end":348,"change":57,"change_pct":19.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Other non-cyber incident","base":1502,"end":1697,"change":195,"change_pct":13,"meets_min_base":true,"catch_all":true},{"incident_type":"Loss/theft of paperwork or data left in insecure location","base":610,"end":588,"change":-22,"change_pct":-3.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Loss/theft of device containing personal data","base":168,"end":154,"change":-14,"change_pct":-8.3,"meets_min_base":true,"catch_all":false},{"incident_type":"Data posted or faxed to incorrect recipient","base":831,"end":735,"change":-96,"change_pct":-11.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Malware","base":116,"end":102,"change":-14,"change_pct":-12.1,"meets_min_base":true,"catch_all":false},{"incident_type":"Ransomware","base":723,"end":617,"change":-106,"change_pct":-14.7,"meets_min_base":true,"catch_all":false},{"incident_type":"Alteration of personal data","base":30,"end":11,"change":-19,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Brute Force","base":79,"end":45,"change":-34,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Cryptographic flaw","base":2,"end":0,"change":-2,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Denial of service","base":13,"end":3,"change":-10,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of hardware","base":8,"end":9,"change":1,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of paperwork","base":36,"end":38,"change":2,"change_pct":null,"meets_min_base":false,"catch_all":false}],"falls_provisional":{"label":"provisional: depends on 2025-Q4, which has 649 uncoded reports","reading":"Every fall in this window ends in 2025 and so depends on the provisional 2025-Q4, where 649 reports have no incident type yet. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. See revisions.newest_quarter_downward_type_revisions. The Q1-Q3 figures compare the first three quarters of 2021 and 2025. Rises and highs are less exposed, since assigning the uncoded reports adds to named types, but named-type counts have also been revised down before, so they are not fixed either.","checks":[{"incident_type":"Loss/theft of paperwork or data left in insecure location","full_period":{"base":610,"end":588,"change_pct":-3.6},"q1_q3":{"base":478,"end":460,"change":-18,"change_pct":-3.8,"meets_min_base":true},"status":"provisional"},{"incident_type":"Loss/theft of device containing personal data","full_period":{"base":168,"end":154,"change_pct":-8.3},"q1_q3":{"base":124,"end":123,"change":-1,"change_pct":-0.8,"meets_min_base":true},"status":"provisional"},{"incident_type":"Data posted or faxed to incorrect recipient","full_period":{"base":831,"end":735,"change_pct":-11.6},"q1_q3":{"base":650,"end":547,"change":-103,"change_pct":-15.8,"meets_min_base":true},"status":"provisional"},{"incident_type":"Malware","full_period":{"base":116,"end":102,"change_pct":-12.1},"q1_q3":{"base":93,"end":82,"change":-11,"change_pct":null,"meets_min_base":false},"status":"provisional"},{"incident_type":"Ransomware","full_period":{"base":723,"end":617,"change_pct":-14.7},"q1_q3":{"base":534,"end":469,"change":-65,"change_pct":-12.2,"meets_min_base":true},"status":"provisional"}]}},{"window":"2024 to 2025","base_quarters":["2024-Q1","2024-Q4"],"end_quarters":["2025-Q1","2025-Q4"],"note":"One-year window. 2025-Q4 is a first release with 649 \"Not Provided\" types.","all_reports":{"base":12195,"end":13457,"change_pct":10.3},"not_provided":{"base":121,"end":788},"fastest_growing_named_types":["Unauthorised access","Failure to redact","Phishing","Data emailed to incorrect recipient","Data of wrong data subject shown in client portal"],"falling_named_types":["Data posted or faxed to incorrect recipient","Hardware/software misconfiguration","Malware","Loss/theft of device containing personal data","Ransomware"],"types":[{"incident_type":"Unauthorised access","base":1328,"end":1597,"change":269,"change_pct":20.3,"meets_min_base":true,"catch_all":false,"note":"Both ICO categories combined (the Cyber/Non Cyber split changed over time; see unauthorised_access_coding)."},{"incident_type":"Failure to redact","base":751,"end":886,"change":135,"change_pct":18,"meets_min_base":true,"catch_all":false},{"incident_type":"Phishing","base":1380,"end":1526,"change":146,"change_pct":10.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Data emailed to incorrect recipient","base":2228,"end":2459,"change":231,"change_pct":10.4,"meets_min_base":true,"catch_all":false},{"incident_type":"Data of wrong data subject shown in client portal","base":208,"end":228,"change":20,"change_pct":9.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Other cyber incident","base":721,"end":770,"change":49,"change_pct":6.8,"meets_min_base":true,"catch_all":true},{"incident_type":"Failure to use bcc","base":416,"end":434,"change":18,"change_pct":4.3,"meets_min_base":true,"catch_all":false},{"incident_type":"Verbal disclosure of personal data","base":339,"end":348,"change":9,"change_pct":2.7,"meets_min_base":true,"catch_all":false},{"incident_type":"Other non-cyber incident","base":1685,"end":1697,"change":12,"change_pct":0.7,"meets_min_base":true,"catch_all":true},{"incident_type":"Loss/theft of paperwork or data left in insecure location","base":584,"end":588,"change":4,"change_pct":0.7,"meets_min_base":true,"catch_all":false},{"incident_type":"Data posted or faxed to incorrect recipient","base":738,"end":735,"change":-3,"change_pct":-0.4,"meets_min_base":true,"catch_all":false},{"incident_type":"Hardware/software misconfiguration","base":478,"end":422,"change":-56,"change_pct":-11.7,"meets_min_base":true,"catch_all":false,"note":"Coded Non Cyber in every row-level release; listed under cyber in the FY2021/22 aggregate tables."},{"incident_type":"Malware","base":122,"end":102,"change":-20,"change_pct":-16.4,"meets_min_base":true,"catch_all":false},{"incident_type":"Loss/theft of device containing personal data","base":186,"end":154,"change":-32,"change_pct":-17.2,"meets_min_base":true,"catch_all":false},{"incident_type":"Ransomware","base":752,"end":617,"change":-135,"change_pct":-18,"meets_min_base":true,"catch_all":false},{"incident_type":"Alteration of personal data","base":8,"end":11,"change":3,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Brute Force","base":88,"end":45,"change":-43,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Cryptographic flaw","base":0,"end":0,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Denial of service","base":3,"end":3,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of hardware","base":4,"end":9,"change":5,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of paperwork","base":55,"end":38,"change":-17,"change_pct":null,"meets_min_base":false,"catch_all":false}],"falls_provisional":{"label":"provisional: depends on 2025-Q4, which has 649 uncoded reports","reading":"Every fall in this window ends in 2025 and so depends on the provisional 2025-Q4, where 649 reports have no incident type yet. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. See revisions.newest_quarter_downward_type_revisions. The Q1-Q3 figures compare the first three quarters of 2024 and 2025. Rises and highs are less exposed, since assigning the uncoded reports adds to named types, but named-type counts have also been revised down before, so they are not fixed either.","checks":[{"incident_type":"Data posted or faxed to incorrect recipient","full_period":{"base":738,"end":735,"change_pct":-0.4},"q1_q3":{"base":571,"end":547,"change":-24,"change_pct":-4.2,"meets_min_base":true},"status":"provisional"},{"incident_type":"Hardware/software misconfiguration","full_period":{"base":478,"end":422,"change_pct":-11.7},"q1_q3":{"base":358,"end":329,"change":-29,"change_pct":-8.1,"meets_min_base":true},"status":"provisional"},{"incident_type":"Malware","full_period":{"base":122,"end":102,"change_pct":-16.4},"q1_q3":{"base":76,"end":82,"change":6,"change_pct":null,"meets_min_base":false},"status":"provisional"},{"incident_type":"Loss/theft of device containing personal data","full_period":{"base":186,"end":154,"change_pct":-17.2},"q1_q3":{"base":133,"end":123,"change":-10,"change_pct":-7.5,"meets_min_base":true},"status":"provisional"},{"incident_type":"Ransomware","full_period":{"base":752,"end":617,"change_pct":-18},"q1_q3":{"base":603,"end":469,"change":-134,"change_pct":-22.2,"meets_min_base":true},"status":"provisional"}]}},{"window":"2024 Q1-Q3 to 2025 Q1-Q3","base_quarters":["2024-Q1","2024-Q3"],"end_quarters":["2025-Q1","2025-Q3"],"note":"Robustness check that leaves out the less complete 2025-Q4.","all_reports":{"base":9036,"end":9780,"change_pct":8.2},"not_provided":{"base":84,"end":139},"fastest_growing_named_types":["Failure to redact","Unauthorised access","Failure to use bcc","Data emailed to incorrect recipient","Verbal disclosure of personal data"],"falling_named_types":["Data of wrong data subject shown in client portal","Data posted or faxed to incorrect recipient","Loss/theft of device containing personal data","Hardware/software misconfiguration","Ransomware"],"types":[{"incident_type":"Failure to redact","base":519,"end":685,"change":166,"change_pct":32,"meets_min_base":true,"catch_all":false},{"incident_type":"Unauthorised access","base":1011,"end":1224,"change":213,"change_pct":21.1,"meets_min_base":true,"catch_all":false,"note":"Both ICO categories combined (the Cyber/Non Cyber split changed over time; see unauthorised_access_coding)."},{"incident_type":"Failure to use bcc","base":284,"end":338,"change":54,"change_pct":19,"meets_min_base":true,"catch_all":false},{"incident_type":"Data emailed to incorrect recipient","base":1574,"end":1852,"change":278,"change_pct":17.7,"meets_min_base":true,"catch_all":false},{"incident_type":"Verbal disclosure of personal data","base":240,"end":277,"change":37,"change_pct":15.4,"meets_min_base":true,"catch_all":false},{"incident_type":"Other non-cyber incident","base":1244,"end":1377,"change":133,"change_pct":10.7,"meets_min_base":true,"catch_all":true},{"incident_type":"Loss/theft of paperwork or data left in insecure location","base":426,"end":460,"change":34,"change_pct":8,"meets_min_base":true,"catch_all":false},{"incident_type":"Phishing","base":1078,"end":1097,"change":19,"change_pct":1.8,"meets_min_base":true,"catch_all":false},{"incident_type":"Other cyber incident","base":550,"end":549,"change":-1,"change_pct":-0.2,"meets_min_base":true,"catch_all":true},{"incident_type":"Data of wrong data subject shown in client portal","base":160,"end":156,"change":-4,"change_pct":-2.5,"meets_min_base":true,"catch_all":false},{"incident_type":"Data posted or faxed to incorrect recipient","base":571,"end":547,"change":-24,"change_pct":-4.2,"meets_min_base":true,"catch_all":false},{"incident_type":"Loss/theft of device containing personal data","base":133,"end":123,"change":-10,"change_pct":-7.5,"meets_min_base":true,"catch_all":false},{"incident_type":"Hardware/software misconfiguration","base":358,"end":329,"change":-29,"change_pct":-8.1,"meets_min_base":true,"catch_all":false,"note":"Coded Non Cyber in every row-level release; listed under cyber in the FY2021/22 aggregate tables."},{"incident_type":"Ransomware","base":603,"end":469,"change":-134,"change_pct":-22.2,"meets_min_base":true,"catch_all":false},{"incident_type":"Alteration of personal data","base":4,"end":9,"change":5,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Brute Force","base":79,"end":26,"change":-53,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Cryptographic flaw","base":0,"end":0,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Denial of service","base":1,"end":1,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of hardware","base":3,"end":5,"change":2,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of paperwork","base":38,"end":35,"change":-3,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Malware","base":76,"end":82,"change":6,"change_pct":null,"meets_min_base":false,"catch_all":false}]},{"window":"2021 Q1-Q3 to 2025 Q1-Q3","base_quarters":["2021-Q1","2021-Q3"],"end_quarters":["2025-Q1","2025-Q3"],"note":"Robustness check for the four-year window that leaves out the less complete 2025-Q4.","all_reports":{"base":7348,"end":9780,"change_pct":33.1},"not_provided":{"base":140,"end":139},"fastest_growing_named_types":["Hardware/software misconfiguration","Failure to redact","Failure to use bcc","Unauthorised access","Data emailed to incorrect recipient"],"falling_named_types":["Loss/theft of device containing personal data","Loss/theft of paperwork or data left in insecure location","Ransomware","Data posted or faxed to incorrect recipient"],"types":[{"incident_type":"Other cyber incident","base":223,"end":549,"change":326,"change_pct":146.2,"meets_min_base":true,"catch_all":true},{"incident_type":"Hardware/software misconfiguration","base":142,"end":329,"change":187,"change_pct":131.7,"meets_min_base":true,"catch_all":false,"note":"Coded Non Cyber in every row-level release; listed under cyber in the FY2021/22 aggregate tables."},{"incident_type":"Failure to redact","base":310,"end":685,"change":375,"change_pct":121,"meets_min_base":true,"catch_all":false},{"incident_type":"Failure to use bcc","base":195,"end":338,"change":143,"change_pct":73.3,"meets_min_base":true,"catch_all":false},{"incident_type":"Unauthorised access","base":812,"end":1224,"change":412,"change_pct":50.7,"meets_min_base":true,"catch_all":false,"note":"Both ICO categories combined (the Cyber/Non Cyber split changed over time; see unauthorised_access_coding)."},{"incident_type":"Data emailed to incorrect recipient","base":1272,"end":1852,"change":580,"change_pct":45.6,"meets_min_base":true,"catch_all":false},{"incident_type":"Verbal disclosure of personal data","base":206,"end":277,"change":71,"change_pct":34.5,"meets_min_base":true,"catch_all":false},{"incident_type":"Phishing","base":820,"end":1097,"change":277,"change_pct":33.8,"meets_min_base":true,"catch_all":false},{"incident_type":"Other non-cyber incident","base":1154,"end":1377,"change":223,"change_pct":19.3,"meets_min_base":true,"catch_all":true},{"incident_type":"Loss/theft of device containing personal data","base":124,"end":123,"change":-1,"change_pct":-0.8,"meets_min_base":true,"catch_all":false},{"incident_type":"Loss/theft of paperwork or data left in insecure location","base":478,"end":460,"change":-18,"change_pct":-3.8,"meets_min_base":true,"catch_all":false},{"incident_type":"Ransomware","base":534,"end":469,"change":-65,"change_pct":-12.2,"meets_min_base":true,"catch_all":false},{"incident_type":"Data posted or faxed to incorrect recipient","base":650,"end":547,"change":-103,"change_pct":-15.8,"meets_min_base":true,"catch_all":false},{"incident_type":"Alteration of personal data","base":14,"end":9,"change":-5,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Brute Force","base":68,"end":26,"change":-42,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Cryptographic flaw","base":0,"end":0,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Data of wrong data subject shown in client portal","base":73,"end":156,"change":83,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Denial of service","base":12,"end":1,"change":-11,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of hardware","base":5,"end":5,"change":0,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Incorrect disposal of paperwork","base":23,"end":35,"change":12,"change_pct":null,"meets_min_base":false,"catch_all":false},{"incident_type":"Malware","base":93,"end":82,"change":-11,"change_pct":null,"meets_min_base":false,"catch_all":false}]}],"caveats":["Growth is reported only where the base period has at least 100 reports.","ICO: \"The way the ICO inputs data changes over time ... caution should be taken when drawing conclusions on changes in specific sectors, incident types or outcomes.\"","Counts of reports can rise because more incidents occur, because more are reported, or because coding practice changes; this data cannot separate these.","Falls to 2025 are provisional: 2025-Q4 has 649 reports with no incident type. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. See revisions.newest_quarter_downward_type_revisions. Each full-year window that ends in 2025 lists its falls under falls_provisional with the Q1-Q3 figures alongside."]},"sector_cyber_league":{"title":"Sector league tables for cyber incidents (with n)","tables":[{"period":"2025","quarters":["2025-Q1","2025-Q4"],"min_n_for_share_rank":100,"sectors":[{"sector":"Retail and manufacture","reports":1497,"cyber_ico":805,"cyber_share_ico_pct":53.8,"always_cyber_types":796,"always_cyber_share_of_typed_pct":54.4,"ransomware":227,"phishing":322,"meets_min_n":true,"rank_by_cyber_count":1,"rank_by_cyber_share":1},{"sector":"Finance, insurance and credit","reports":1069,"cyber_ico":400,"cyber_share_ico_pct":37.4,"always_cyber_types":382,"always_cyber_share_of_typed_pct":37.5,"ransomware":76,"phishing":176,"meets_min_n":true,"rank_by_cyber_count":2,"rank_by_cyber_share":4},{"sector":"Transport and leisure","reports":535,"cyber_ico":284,"cyber_share_ico_pct":53.1,"always_cyber_types":276,"always_cyber_share_of_typed_pct":54,"ransomware":32,"phishing":112,"meets_min_n":true,"rank_by_cyber_count":3,"rank_by_cyber_share":2},{"sector":"Education and childcare","reports":1830,"cyber_ico":259,"cyber_share_ico_pct":14.2,"always_cyber_types":251,"always_cyber_share_of_typed_pct":14.5,"ransomware":44,"phishing":156,"meets_min_n":true,"rank_by_cyber_count":4,"rank_by_cyber_share":11},{"sector":"Charitable and voluntary","reports":979,"cyber_ico":229,"cyber_share_ico_pct":23.4,"always_cyber_types":223,"always_cyber_share_of_typed_pct":24.2,"ransomware":19,"phishing":158,"meets_min_n":true,"rank_by_cyber_count":5,"rank_by_cyber_share":9},{"sector":"Legal","reports":962,"cyber_ico":220,"cyber_share_ico_pct":22.9,"always_cyber_types":218,"always_cyber_share_of_typed_pct":24,"ransomware":42,"phishing":153,"meets_min_n":true,"rank_by_cyber_count":6,"rank_by_cyber_share":10},{"sector":"Land or property services","reports":768,"cyber_ico":208,"cyber_share_ico_pct":27.1,"always_cyber_types":205,"always_cyber_share_of_typed_pct":28.4,"ransomware":39,"phishing":129,"meets_min_n":true,"rank_by_cyber_count":7,"rank_by_cyber_share":7},{"sector":"Health","reports":2471,"cyber_ico":182,"cyber_share_ico_pct":7.4,"always_cyber_types":175,"always_cyber_share_of_typed_pct":7.5,"ransomware":22,"phishing":98,"meets_min_n":true,"rank_by_cyber_count":8,"rank_by_cyber_share":13},{"sector":"Online Technology and Telecoms","reports":338,"cyber_ico":170,"cyber_share_ico_pct":50.3,"always_cyber_types":161,"always_cyber_share_of_typed_pct":49.5,"ransomware":39,"phishing":49,"meets_min_n":true,"rank_by_cyber_count":9,"rank_by_cyber_share":3},{"sector":"General business","reports":292,"cyber_ico":105,"cyber_share_ico_pct":36,"always_cyber_types":100,"always_cyber_share_of_typed_pct":38,"ransomware":20,"phishing":46,"meets_min_n":true,"rank_by_cyber_count":10,"rank_by_cyber_share":5},{"sector":"Membership association","reports":201,"cyber_ico":56,"cyber_share_ico_pct":27.9,"always_cyber_types":52,"always_cyber_share_of_typed_pct":26.9,"ransomware":6,"phishing":29,"meets_min_n":true,"rank_by_cyber_count":11,"rank_by_cyber_share":6},{"sector":"Local government","reports":1080,"cyber_ico":50,"cyber_share_ico_pct":4.6,"always_cyber_types":47,"always_cyber_share_of_typed_pct":4.8,"ransomware":19,"phishing":11,"meets_min_n":true,"rank_by_cyber_count":12,"rank_by_cyber_share":15},{"sector":"Social care","reports":479,"cyber_ico":45,"cyber_share_ico_pct":9.4,"always_cyber_types":42,"always_cyber_share_of_typed_pct":9.2,"ransomware":2,"phishing":25,"meets_min_n":true,"rank_by_cyber_count":13,"rank_by_cyber_share":12},{"sector":"Marketing","reports":69,"cyber_ico":42,"cyber_share_ico_pct":60.9,"always_cyber_types":42,"always_cyber_share_of_typed_pct":61.8,"ransomware":7,"phishing":22,"meets_min_n":false,"rank_by_cyber_count":14},{"sector":"Utilities","reports":135,"cyber_ico":32,"cyber_share_ico_pct":23.7,"always_cyber_types":29,"always_cyber_share_of_typed_pct":22.8,"ransomware":10,"phishing":13,"meets_min_n":true,"rank_by_cyber_count":15,"rank_by_cyber_share":8},{"sector":"Media","reports":32,"cyber_ico":20,"cyber_share_ico_pct":62.5,"always_cyber_types":19,"always_cyber_share_of_typed_pct":61.3,"ransomware":4,"phishing":9,"meets_min_n":false,"rank_by_cyber_count":16},{"sector":"Central Government","reports":208,"cyber_ico":13,"cyber_share_ico_pct":6.3,"always_cyber_types":12,"always_cyber_share_of_typed_pct":6.5,"ransomware":2,"phishing":4,"meets_min_n":true,"rank_by_cyber_count":17,"rank_by_cyber_share":14},{"sector":"Religious","reports":57,"cyber_ico":13,"cyber_share_ico_pct":22.8,"always_cyber_types":13,"always_cyber_share_of_typed_pct":24.1,"ransomware":0,"phishing":10,"meets_min_n":false,"rank_by_cyber_count":18},{"sector":"Regulators","reports":59,"cyber_ico":7,"cyber_share_ico_pct":11.9,"always_cyber_types":7,"always_cyber_share_of_typed_pct":12.3,"ransomware":1,"phishing":2,"meets_min_n":false,"rank_by_cyber_count":19},{"sector":"Justice","reports":257,"cyber_ico":5,"cyber_share_ico_pct":1.9,"always_cyber_types":5,"always_cyber_share_of_typed_pct":2,"ransomware":3,"phishing":0,"meets_min_n":true,"rank_by_cyber_count":20,"rank_by_cyber_share":16},{"sector":"Political","reports":41,"cyber_ico":3,"cyber_share_ico_pct":7.3,"always_cyber_types":3,"always_cyber_share_of_typed_pct":7.5,"ransomware":0,"phishing":1,"meets_min_n":false,"rank_by_cyber_count":21}]},{"period":"2024-2025","quarters":["2024-Q1","2025-Q4"],"min_n_for_share_rank":100,"sectors":[{"sector":"Retail and manufacture","reports":2831,"cyber_ico":1578,"cyber_share_ico_pct":55.7,"always_cyber_types":1558,"always_cyber_share_of_typed_pct":55.9,"ransomware":457,"phishing":609,"meets_min_n":true,"rank_by_cyber_count":1,"rank_by_cyber_share":2},{"sector":"Finance, insurance and credit","reports":2043,"cyber_ico":757,"cyber_share_ico_pct":37.1,"always_cyber_types":730,"always_cyber_share_of_typed_pct":36.9,"ransomware":159,"phishing":355,"meets_min_n":true,"rank_by_cyber_count":2,"rank_by_cyber_share":6},{"sector":"Education and childcare","reports":3542,"cyber_ico":537,"cyber_share_ico_pct":15.2,"always_cyber_types":527,"always_cyber_share_of_typed_pct":15.4,"ransomware":126,"phishing":297,"meets_min_n":true,"rank_by_cyber_count":3,"rank_by_cyber_share":13},{"sector":"Transport and leisure","reports":973,"cyber_ico":489,"cyber_share_ico_pct":50.3,"always_cyber_types":475,"always_cyber_share_of_typed_pct":50.3,"ransomware":61,"phishing":204,"meets_min_n":true,"rank_by_cyber_count":4,"rank_by_cyber_share":4},{"sector":"Legal","reports":1757,"cyber_ico":452,"cyber_share_ico_pct":25.7,"always_cyber_types":447,"always_cyber_share_of_typed_pct":26.3,"ransomware":64,"phishing":327,"meets_min_n":true,"rank_by_cyber_count":5,"rank_by_cyber_share":9},{"sector":"Charitable and voluntary","reports":1825,"cyber_ico":446,"cyber_share_ico_pct":24.4,"always_cyber_types":436,"always_cyber_share_of_typed_pct":24.7,"ransomware":59,"phishing":279,"meets_min_n":true,"rank_by_cyber_count":6,"rank_by_cyber_share":10},{"sector":"Health","reports":4913,"cyber_ico":411,"cyber_share_ico_pct":8.4,"always_cyber_types":401,"always_cyber_share_of_typed_pct":8.4,"ransomware":100,"phishing":163,"meets_min_n":true,"rank_by_cyber_count":7,"rank_by_cyber_share":16},{"sector":"Land or property services","reports":1354,"cyber_ico":386,"cyber_share_ico_pct":28.5,"always_cyber_types":383,"always_cyber_share_of_typed_pct":29.4,"ransomware":73,"phishing":221,"meets_min_n":true,"rank_by_cyber_count":8,"rank_by_cyber_share":8},{"sector":"Online Technology and Telecoms","reports":648,"cyber_ico":344,"cyber_share_ico_pct":53.1,"always_cyber_types":333,"always_cyber_share_of_typed_pct":53,"ransomware":95,"phishing":79,"meets_min_n":true,"rank_by_cyber_count":9,"rank_by_cyber_share":3},{"sector":"General business","reports":565,"cyber_ico":210,"cyber_share_ico_pct":37.2,"always_cyber_types":205,"always_cyber_share_of_typed_pct":38.5,"ransomware":45,"phishing":96,"meets_min_n":true,"rank_by_cyber_count":10,"rank_by_cyber_share":5},{"sector":"Local government","reports":2228,"cyber_ico":172,"cyber_share_ico_pct":7.7,"always_cyber_types":166,"always_cyber_share_of_typed_pct":7.9,"ransomware":60,"phishing":33,"meets_min_n":true,"rank_by_cyber_count":11,"rank_by_cyber_share":17},{"sector":"Membership association","reports":396,"cyber_ico":126,"cyber_share_ico_pct":31.8,"always_cyber_types":121,"always_cyber_share_of_typed_pct":31.2,"ransomware":20,"phishing":61,"meets_min_n":true,"rank_by_cyber_count":12,"rank_by_cyber_share":7},{"sector":"Social care","reports":877,"cyber_ico":104,"cyber_share_ico_pct":11.9,"always_cyber_types":100,"always_cyber_share_of_typed_pct":11.7,"ransomware":7,"phishing":64,"meets_min_n":true,"rank_by_cyber_count":13,"rank_by_cyber_share":14},{"sector":"Marketing","reports":138,"cyber_ico":84,"cyber_share_ico_pct":60.9,"always_cyber_types":83,"always_cyber_share_of_typed_pct":61.5,"ransomware":14,"phishing":44,"meets_min_n":true,"rank_by_cyber_count":14,"rank_by_cyber_share":1},{"sector":"Utilities","reports":248,"cyber_ico":57,"cyber_share_ico_pct":23,"always_cyber_types":52,"always_cyber_share_of_typed_pct":21.8,"ransomware":11,"phishing":26,"meets_min_n":true,"rank_by_cyber_count":15,"rank_by_cyber_share":11},{"sector":"Media","reports":52,"cyber_ico":32,"cyber_share_ico_pct":61.5,"always_cyber_types":31,"always_cyber_share_of_typed_pct":60.8,"ransomware":4,"phishing":15,"meets_min_n":false,"rank_by_cyber_count":16},{"sector":"Central Government","reports":427,"cyber_ico":31,"cyber_share_ico_pct":7.3,"always_cyber_types":29,"always_cyber_share_of_typed_pct":7.3,"ransomware":4,"phishing":8,"meets_min_n":true,"rank_by_cyber_count":17,"rank_by_cyber_share":18},{"sector":"Religious","reports":105,"cyber_ico":22,"cyber_share_ico_pct":21,"always_cyber_types":22,"always_cyber_share_of_typed_pct":21.6,"ransomware":1,"phishing":18,"meets_min_n":true,"rank_by_cyber_count":18,"rank_by_cyber_share":12},{"sector":"Regulators","reports":104,"cyber_ico":11,"cyber_share_ico_pct":10.6,"always_cyber_types":11,"always_cyber_share_of_typed_pct":10.9,"ransomware":2,"phishing":4,"meets_min_n":true,"rank_by_cyber_count":19,"rank_by_cyber_share":15},{"sector":"Justice","reports":456,"cyber_ico":10,"cyber_share_ico_pct":2.2,"always_cyber_types":9,"always_cyber_share_of_typed_pct":2,"ransomware":3,"phishing":0,"meets_min_n":true,"rank_by_cyber_count":20,"rank_by_cyber_share":19},{"sector":"Political","reports":72,"cyber_ico":5,"cyber_share_ico_pct":6.9,"always_cyber_types":5,"always_cyber_share_of_typed_pct":7,"ransomware":1,"phishing":2,"meets_min_n":false,"rank_by_cyber_count":21}]},{"period":"2019-2025 (all quarters in file)","quarters":["2019-Q1","2025-Q4"],"min_n_for_share_rank":100,"sectors":[{"sector":"Retail and manufacture","reports":7293,"cyber_ico":3937,"cyber_share_ico_pct":54,"always_cyber_types":3569,"always_cyber_share_of_typed_pct":50,"ransomware":1168,"phishing":1282,"meets_min_n":true,"rank_by_cyber_count":1,"rank_by_cyber_share":2},{"sector":"Finance, insurance and credit","reports":7186,"cyber_ico":2639,"cyber_share_ico_pct":36.7,"always_cyber_types":2448,"always_cyber_share_of_typed_pct":35.3,"ransomware":807,"phishing":936,"meets_min_n":true,"rank_by_cyber_count":2,"rank_by_cyber_share":7},{"sector":"Education and childcare","reports":10729,"cyber_ico":1957,"cyber_share_ico_pct":18.2,"always_cyber_types":1758,"always_cyber_share_of_typed_pct":17,"ransomware":499,"phishing":920,"meets_min_n":true,"rank_by_cyber_count":3,"rank_by_cyber_share":14},{"sector":"General business","reports":3715,"cyber_ico":1556,"cyber_share_ico_pct":41.9,"always_cyber_types":1197,"always_cyber_share_of_typed_pct":33.9,"ransomware":232,"phishing":677,"meets_min_n":true,"rank_by_cyber_count":4,"rank_by_cyber_share":6},{"sector":"Legal","reports":5616,"cyber_ico":1429,"cyber_share_ico_pct":25.4,"always_cyber_types":1335,"always_cyber_share_of_typed_pct":24.6,"ransomware":223,"phishing":913,"meets_min_n":true,"rank_by_cyber_count":5,"rank_by_cyber_share":11},{"sector":"Health","reports":14308,"cyber_ico":1199,"cyber_share_ico_pct":8.4,"always_cyber_types":1055,"always_cyber_share_of_typed_pct":7.6,"ransomware":316,"phishing":434,"meets_min_n":true,"rank_by_cyber_count":6,"rank_by_cyber_share":17},{"sector":"Charitable and voluntary","reports":4654,"cyber_ico":1175,"cyber_share_ico_pct":25.2,"always_cyber_types":1102,"always_cyber_share_of_typed_pct":24.4,"ransomware":216,"phishing":642,"meets_min_n":true,"rank_by_cyber_count":7,"rank_by_cyber_share":12},{"sector":"Transport and leisure","reports":2570,"cyber_ico":1135,"cyber_share_ico_pct":44.2,"always_cyber_types":1018,"always_cyber_share_of_typed_pct":41,"ransomware":224,"phishing":423,"meets_min_n":true,"rank_by_cyber_count":8,"rank_by_cyber_share":5},{"sector":"Land or property services","reports":3618,"cyber_ico":1033,"cyber_share_ico_pct":28.6,"always_cyber_types":976,"always_cyber_share_of_typed_pct":27.9,"ransomware":217,"phishing":572,"meets_min_n":true,"rank_by_cyber_count":9,"rank_by_cyber_share":8},{"sector":"Online Technology and Telecoms","reports":1905,"cyber_ico":986,"cyber_share_ico_pct":51.8,"always_cyber_types":861,"always_cyber_share_of_typed_pct":46.7,"ransomware":260,"phishing":253,"meets_min_n":true,"rank_by_cyber_count":10,"rank_by_cyber_share":3},{"sector":"Local government","reports":6903,"cyber_ico":518,"cyber_share_ico_pct":7.5,"always_cyber_types":488,"always_cyber_share_of_typed_pct":7.3,"ransomware":242,"phishing":116,"meets_min_n":true,"rank_by_cyber_count":11,"rank_by_cyber_share":18},{"sector":"Membership association","reports":1078,"cyber_ico":303,"cyber_share_ico_pct":28.1,"always_cyber_types":281,"always_cyber_share_of_typed_pct":26.8,"ransomware":70,"phishing":125,"meets_min_n":true,"rank_by_cyber_count":12,"rank_by_cyber_share":9},{"sector":"Social care","reports":2065,"cyber_ico":268,"cyber_share_ico_pct":13,"always_cyber_types":252,"always_cyber_share_of_typed_pct":12.5,"ransomware":40,"phishing":170,"meets_min_n":true,"rank_by_cyber_count":13,"rank_by_cyber_share":15},{"sector":"Utilities","reports":749,"cyber_ico":176,"cyber_share_ico_pct":23.5,"always_cyber_types":157,"always_cyber_share_of_typed_pct":21.8,"ransomware":56,"phishing":58,"meets_min_n":true,"rank_by_cyber_count":14,"rank_by_cyber_share":13},{"sector":"Marketing","reports":280,"cyber_ico":155,"cyber_share_ico_pct":55.4,"always_cyber_types":144,"always_cyber_share_of_typed_pct":52.7,"ransomware":34,"phishing":74,"meets_min_n":true,"rank_by_cyber_count":15,"rank_by_cyber_share":1},{"sector":"Central Government","reports":2132,"cyber_ico":127,"cyber_share_ico_pct":6,"always_cyber_types":99,"always_cyber_share_of_typed_pct":4.9,"ransomware":24,"phishing":32,"meets_min_n":true,"rank_by_cyber_count":16,"rank_by_cyber_share":19},{"sector":"Media","reports":215,"cyber_ico":106,"cyber_share_ico_pct":49.3,"always_cyber_types":85,"always_cyber_share_of_typed_pct":40.9,"ransomware":20,"phishing":32,"meets_min_n":true,"rank_by_cyber_count":17,"rank_by_cyber_share":4},{"sector":"Religious","reports":293,"cyber_ico":79,"cyber_share_ico_pct":27,"always_cyber_types":71,"always_cyber_share_of_typed_pct":25,"ransomware":14,"phishing":47,"meets_min_n":true,"rank_by_cyber_count":18,"rank_by_cyber_share":10},{"sector":"Justice","reports":1317,"cyber_ico":37,"cyber_share_ico_pct":2.8,"always_cyber_types":33,"always_cyber_share_of_typed_pct":2.6,"ransomware":15,"phishing":2,"meets_min_n":true,"rank_by_cyber_count":19,"rank_by_cyber_share":21},{"sector":"Regulators","reports":303,"cyber_ico":37,"cyber_share_ico_pct":12.2,"always_cyber_types":34,"always_cyber_share_of_typed_pct":11.7,"ransomware":6,"phishing":15,"meets_min_n":true,"rank_by_cyber_count":20,"rank_by_cyber_share":16},{"sector":"Political","reports":190,"cyber_ico":10,"cyber_share_ico_pct":5.3,"always_cyber_types":10,"always_cyber_share_of_typed_pct":5.4,"ransomware":3,"phishing":4,"meets_min_n":true,"rank_by_cyber_count":21,"rank_by_cyber_share":20}]}],"caveats":["Rank by count reflects both the number of reports and the size of the sector; share of own reports removes size but is still not a rate per organisation.","Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.","The ICO cyber share inherits the change over time in how Unauthorised access reports are split between Cyber and Non Cyber; the always-cyber share is the constant-definition alternative.","Sector is allocated by the ICO as a best fit.","Ranks by share use the unrounded ratio."]},"time_to_report":{"title":"Time from discovery to report","by_year":[{"group":"2019","reports":12259,"within_72h_pct":63.3,"more_than_1_week_pct":16.3},{"group":"2020","reports":9702,"within_72h_pct":63.4,"more_than_1_week_pct":16.8},{"group":"2021","reports":9742,"within_72h_pct":64,"more_than_1_week_pct":17.1},{"group":"2022","reports":8798,"within_72h_pct":57.8,"more_than_1_week_pct":20},{"group":"2023","reports":11069,"within_72h_pct":57.4,"more_than_1_week_pct":20.4},{"group":"2024","reports":12195,"within_72h_pct":60.3,"more_than_1_week_pct":18.6},{"group":"2025","reports":13457,"within_72h_pct":63.4,"more_than_1_week_pct":19}],"by_type_2024_2025":[{"group":"Ransomware","reports":1369,"within_72h_pct":61,"more_than_1_week_pct":18.6},{"group":"Phishing","reports":2906,"within_72h_pct":67.7,"more_than_1_week_pct":12.4},{"group":"Data emailed to incorrect recipient","reports":4687,"within_72h_pct":70.1,"more_than_1_week_pct":12.6},{"group":"Unauthorised access","reports":2925,"within_72h_pct":52.2,"more_than_1_week_pct":28.9},{"group":"Hardware/software misconfiguration","reports":900,"within_72h_pct":53.8,"more_than_1_week_pct":15.7},{"group":"all reports","reports":25652,"within_72h_pct":61.9,"more_than_1_week_pct":18.8}],"caveats":["ICO: \"Where only a date and not time is provided by an organisation, the case handler will input midnight as the time a breach was discovered. This may mean that some breaches are labelled as being submitted outside the 72 hour window required even when they were reported on time.\"","UK GDPR allows notification \"within 72 hours of becoming aware of the breach, where feasible\" and information in phases; a report after 72 hours is not by itself evidence of a breach of the rules."]},"data_subjects_affected":{"title":"Number of people affected (as estimated at the time of reporting)","by_type_2024_2025":[{"group":"Ransomware","reports":1369,"known":1001,"ten_thousand_plus":111,"ten_thousand_plus_pct_of_known":11.1,"one_to_nine_pct_of_known":8.4},{"group":"Phishing","reports":2906,"known":2589,"ten_thousand_plus":76,"ten_thousand_plus_pct_of_known":2.9,"one_to_nine_pct_of_known":16.5},{"group":"Malware","reports":224,"known":189,"ten_thousand_plus":29,"ten_thousand_plus_pct_of_known":15.3,"one_to_nine_pct_of_known":10.6},{"group":"Hardware/software misconfiguration","reports":900,"known":806,"ten_thousand_plus":87,"ten_thousand_plus_pct_of_known":10.8,"one_to_nine_pct_of_known":19.5},{"group":"Unauthorised access","reports":2925,"known":2693,"ten_thousand_plus":66,"ten_thousand_plus_pct_of_known":2.5,"one_to_nine_pct_of_known":51.6},{"group":"Other cyber incident","reports":1491,"known":1233,"ten_thousand_plus":188,"ten_thousand_plus_pct_of_known":15.2,"one_to_nine_pct_of_known":20.1},{"group":"Data emailed to incorrect recipient","reports":4687,"known":4607,"ten_thousand_plus":11,"ten_thousand_plus_pct_of_known":0.2,"one_to_nine_pct_of_known":82.3},{"group":"all reports","reports":25652,"known":23684,"ten_thousand_plus":701,"ten_thousand_plus_pct_of_known":3,"one_to_nine_pct_of_known":56.3}],"by_year_all":[{"group":"2019","reports":12259,"known":10255,"ten_thousand_plus":209,"ten_thousand_plus_pct_of_known":2,"one_to_nine_pct_of_known":63.2},{"group":"2020","reports":9702,"known":8139,"ten_thousand_plus":227,"ten_thousand_plus_pct_of_known":2.8,"one_to_nine_pct_of_known":59.8},{"group":"2021","reports":9742,"known":6909,"ten_thousand_plus":201,"ten_thousand_plus_pct_of_known":2.9,"one_to_nine_pct_of_known":58.5},{"group":"2022","reports":8798,"known":7253,"ten_thousand_plus":305,"ten_thousand_plus_pct_of_known":4.2,"one_to_nine_pct_of_known":58.6},{"group":"2023","reports":11069,"known":9596,"ten_thousand_plus":367,"ten_thousand_plus_pct_of_known":3.8,"one_to_nine_pct_of_known":53.3},{"group":"2024","reports":12195,"known":10938,"ten_thousand_plus":325,"ten_thousand_plus_pct_of_known":3,"one_to_nine_pct_of_known":56.5},{"group":"2025","reports":13457,"known":12746,"ten_thousand_plus":376,"ten_thousand_plus_pct_of_known":2.9,"one_to_nine_pct_of_known":56.2}],"caveats":["ICO glossary: organisations \"are therefore advised to indicate the maximum number that may be affected\" at the time of reporting; the figure is not updated later.","Percentages use reports with a known band as the denominator; \"Unknown\" counts are shown."]},"ico_decision":{"title":"Outcome recorded by the ICO","by_year_all":[{"group":"2019","reports":12259,"assigned":12259,"investigation_pursued":2080,"investigation_pursued_pct_of_assigned":17,"not_yet_assigned_pct":0},{"group":"2020","reports":9702,"assigned":9702,"investigation_pursued":1857,"investigation_pursued_pct_of_assigned":19.1,"not_yet_assigned_pct":0},{"group":"2021","reports":9742,"assigned":9742,"investigation_pursued":1209,"investigation_pursued_pct_of_assigned":12.4,"not_yet_assigned_pct":0},{"group":"2022","reports":8798,"assigned":8798,"investigation_pursued":555,"investigation_pursued_pct_of_assigned":6.3,"not_yet_assigned_pct":0},{"group":"2023","reports":11069,"assigned":10936,"investigation_pursued":594,"investigation_pursued_pct_of_assigned":5.4,"not_yet_assigned_pct":1.2},{"group":"2024","reports":12195,"assigned":11473,"investigation_pursued":402,"investigation_pursued_pct_of_assigned":3.5,"not_yet_assigned_pct":5.9},{"group":"2025","reports":13457,"assigned":10552,"investigation_pursued":207,"investigation_pursued_pct_of_assigned":2,"not_yet_assigned_pct":21.6}],"by_year_ransomware":[{"group":"2019 ransomware","reports":158,"assigned":158,"investigation_pursued":156,"investigation_pursued_pct_of_assigned":98.7,"not_yet_assigned_pct":0},{"group":"2020 ransomware","reports":447,"assigned":447,"investigation_pursued":446,"investigation_pursued_pct_of_assigned":99.8,"not_yet_assigned_pct":0},{"group":"2021 ransomware","reports":723,"assigned":723,"investigation_pursued":394,"investigation_pursued_pct_of_assigned":54.5,"not_yet_assigned_pct":0},{"group":"2022 ransomware","reports":739,"assigned":739,"investigation_pursued":195,"investigation_pursued_pct_of_assigned":26.4,"not_yet_assigned_pct":0},{"group":"2023 ransomware","reports":1253,"assigned":1253,"investigation_pursued":87,"investigation_pursued_pct_of_assigned":6.9,"not_yet_assigned_pct":0},{"group":"2024 ransomware","reports":752,"assigned":748,"investigation_pursued":27,"investigation_pursued_pct_of_assigned":3.6,"not_yet_assigned_pct":0.5},{"group":"2025 ransomware","reports":617,"assigned":481,"investigation_pursued":18,"investigation_pursued_pct_of_assigned":3.7,"not_yet_assigned_pct":22}],"caveats":["ICO: definitions of \"informal action taken\" and \"no further action\" changed in April 2021.","\"Investigation pursued\" means passed to investigations teams \"to determine what action, if any, is suitable\"; the ICO notes it \"may not necessarily lead to a full investigation\".","Recent quarters carry many \"Not Yet Assigned\" outcomes; shares use assigned reports only."]},"notable_2025_2026":{"title":"Notable in 2025-2026","items":[{"id":"record_year","text":"2025 had the most breach reports of any calendar year in the file: 13,457, 10.3% more than 2024.","values":{"reports_2025":13457,"reports_2024":12195,"change_pct":10.3}},{"id":"record_quarter","text":"2025-Q4 was the highest quarter in the file (3,677 reports).","values":{"quarter":"2025-Q4","reports":3677},"caveat":"Latest quarter, first release: incident type, sector and outcome coding is less complete than for earlier quarters (see revisions)."},{"id":"types_at_series_high","status":"provisional: includes 2025-Q4, which has 649 uncoded reports","text":"Incident types whose 2025 count was their highest of any full year in the file (above every year from 2019 to 2024; at least 100 reports in 2025): Data emailed to incorrect recipient 2,459; Data of wrong data subject shown in client portal 228; Failure to redact 886; Failure to use bcc 434; Other cyber incident 770 (catch-all); Phishing 1,526; Unauthorised access 1,597; Verbal disclosure of personal data 348. These are highs on the current release, which includes the provisional 2025-Q4. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down (the largest fall was 48 reports, Hardware/software misconfiguration in 2023-Q2). Each type's lead over its 2019-2024 high is larger than any downward revision of its own newest-quarter count in the 8 earlier releases compared; leads smaller than the largest downward revision seen for any named type are the least certain: Verbal disclosure of personal data 9; Failure to use bcc 18; Data of wrong data subject shown in client portal 20; Other cyber incident 37.","values":[{"incident_type":"Data emailed to incorrect recipient","reports_2025":2459,"previous_high":2228,"reports_2019":1377,"above_2019":true,"lead_over_2019_2024_high":231,"largest_newest_quarter_downward_revision":1,"catch_all":false,"q1_q3_2024":1574,"q1_q3_2025":1852,"q1_q3_2025_vs_2024_change_pct":17.7,"q1_q3_base_meets_min":true},{"incident_type":"Data of wrong data subject shown in client portal","reports_2025":228,"previous_high":208,"reports_2019":121,"above_2019":true,"lead_over_2019_2024_high":20,"largest_newest_quarter_downward_revision":0,"catch_all":false,"q1_q3_2024":160,"q1_q3_2025":156,"q1_q3_2025_vs_2024_change_pct":-2.5,"q1_q3_base_meets_min":true},{"incident_type":"Failure to redact","reports_2025":886,"previous_high":751,"reports_2019":333,"above_2019":true,"lead_over_2019_2024_high":135,"largest_newest_quarter_downward_revision":0,"catch_all":false,"q1_q3_2024":519,"q1_q3_2025":685,"q1_q3_2025_vs_2024_change_pct":32,"q1_q3_base_meets_min":true},{"incident_type":"Failure to use bcc","reports_2025":434,"previous_high":416,"reports_2019":332,"above_2019":true,"lead_over_2019_2024_high":18,"largest_newest_quarter_downward_revision":0,"catch_all":false,"q1_q3_2024":284,"q1_q3_2025":338,"q1_q3_2025_vs_2024_change_pct":19,"q1_q3_base_meets_min":true},{"incident_type":"Other cyber incident","reports_2025":770,"previous_high":733,"reports_2019":167,"above_2019":true,"lead_over_2019_2024_high":37,"largest_newest_quarter_downward_revision":9,"catch_all":true,"q1_q3_2024":550,"q1_q3_2025":549,"q1_q3_2025_vs_2024_change_pct":-0.2,"q1_q3_base_meets_min":true},{"incident_type":"Phishing","reports_2025":1526,"previous_high":1380,"reports_2019":1103,"above_2019":true,"lead_over_2019_2024_high":146,"largest_newest_quarter_downward_revision":3,"catch_all":false,"q1_q3_2024":1078,"q1_q3_2025":1097,"q1_q3_2025_vs_2024_change_pct":1.8,"q1_q3_base_meets_min":true},{"incident_type":"Unauthorised access","reports_2025":1597,"previous_high":1328,"reports_2019":876,"above_2019":true,"lead_over_2019_2024_high":269,"largest_newest_quarter_downward_revision":2,"catch_all":false,"q1_q3_2024":1011,"q1_q3_2025":1224,"q1_q3_2025_vs_2024_change_pct":21.1,"q1_q3_base_meets_min":true},{"incident_type":"Verbal disclosure of personal data","reports_2025":348,"previous_high":339,"reports_2019":268,"above_2019":true,"lead_over_2019_2024_high":9,"largest_newest_quarter_downward_revision":0,"catch_all":false,"q1_q3_2024":240,"q1_q3_2025":277,"q1_q3_2025_vs_2024_change_pct":15.4,"q1_q3_base_meets_min":true}],"leads_below_largest_downward_revision":["Verbal disclosure of personal data","Failure to use bcc","Data of wrong data subject shown in client portal","Other cyber incident"],"largest_newest_quarter_downward_revision":{"release":"rel-2023Q2","quarter":"2023-Q2","incident_type":"Hardware/software misconfiguration","at_release":107,"now":59,"change":-48}},{"id":"types_at_series_low","status":"provisional: depends on 2025-Q4, which has 649 uncoded reports","text":"Provisional: Loss/theft of device containing personal data had 154 reports in 2025, below every year from 2020 to 2024 (previous low 168); Malware had 102 reports in 2025, below every year from 2020 to 2024 (previous low 103). These lows depend on 2025-Q4, which has 649 reports with no incident type yet. On the first three quarters of each year, none of them is a 2020-2025 low: Loss/theft of device containing personal data 123 in 2025 Q1-Q3 against a lowest of 116 in 2020-2024; Malware 82 in 2025 Q1-Q3 against a lowest of 57 in 2020-2024.","values":[{"incident_type":"Loss/theft of device containing personal data","reports_2025":154,"previous_low":168,"q1_q3_by_year":{"2020":180,"2021":124,"2022":116,"2023":150,"2024":133,"2025":123},"low_also_on_q1_q3":false,"catch_all":false,"q1_q3_2024":133,"q1_q3_2025":123,"q1_q3_2025_vs_2024_change_pct":-7.5,"q1_q3_base_meets_min":true},{"incident_type":"Malware","reports_2025":102,"previous_low":103,"q1_q3_by_year":{"2020":89,"2021":93,"2022":57,"2023":134,"2024":76,"2025":82},"low_also_on_q1_q3":false,"catch_all":false,"q1_q3_2024":76,"q1_q3_2025":82,"q1_q3_2025_vs_2024_change_pct":null,"q1_q3_base_meets_min":false}],"confirmed_on_q1_q3":[]},{"id":"ransomware_2025","text":"Ransomware reports fell to 617 in 2025, the lowest year since 2020, and 4.6% of all reports. The fall does not rest on the provisional 2025-Q4: over the first three quarters, ransomware reports fell from 603 in 2024 to 469 in 2025, also the lowest since 2020.","values":{"ransomware_2025":617,"lowest_since":2020,"share_of_all_pct":4.6,"peak_year":{"year":2023,"ransomware":1253},"ransomware_q1_q3_2024":603,"ransomware_q1_q3_2025":469,"lowest_since_on_q1_q3":2020}},{"id":"ransomware_sector_2025","text":"Retail and manufacture made 227 of the 617 ransomware reports in 2025 (36.8%), and ransomware was 15.2% of that sector's own 1,497 reports.","values":{"sector":"Retail and manufacture","reports":1497,"ransomware":227,"share_of_sector_reports_pct":15.2,"share_of_all_ransomware_pct":36.8}},{"id":"cyber_share_2025","text":"ICO-coded cyber reports were 23.4% of 2025 reports; the constant-definition share (always-cyber types / typed reports) was 24.2%.","values":{"reports":13457,"cyber_ico":3153,"cyber_share_ico_pct":23.4,"always_cyber_types":3063,"type_recorded":12669,"always_cyber_share_of_typed_pct":24.2}},{"id":"latest_quarter_incomplete","text":"2025-Q4 has 649 reports with incident type \"Not Provided\" (17.7% of the quarter), far more than the newest quarter of any of the 8 earlier releases compared (at most 112; see revisions).","values":{"not_provided":649,"reports":3677,"not_provided_pct":17.7,"max_not_provided_in_newest_quarter_of_earlier_releases":112,"earlier_releases_compared":8}},{"id":"no_2026_quarters","text":"No 2026 quarter is published yet: on 2026-09-19 the ICO page's latest update reads \"Data updated to Q4 2025\". The ICO page lists the update as 11 March 2025; the file is dated 11 March 2026. Nothing about 2026 is inferred from this dataset.","values":{"latest_quarter_published":"2025-Q4","file_dated":"2026-03-11","page_lists_update_as":"2025-03-11"}},{"id":"ransomware_investigation_share","text":"Of ransomware reports with an outcome recorded, the share recorded as \"Investigation Pursued\": 2019 98.7%, 2020 99.8%, 2021 54.5%, 2022 26.4%, 2023 6.9%, 2024 3.6%, 2025 3.7%. Outcome definitions changed in April 2021 and 22% of 2025 ransomware outcomes were not yet assigned.","values":[{"year":2019,"reports":158,"assigned":158,"investigation_pursued":156,"investigation_pursued_pct_of_assigned":98.7},{"year":2020,"reports":447,"assigned":447,"investigation_pursued":446,"investigation_pursued_pct_of_assigned":99.8},{"year":2021,"reports":723,"assigned":723,"investigation_pursued":394,"investigation_pursued_pct_of_assigned":54.5},{"year":2022,"reports":739,"assigned":739,"investigation_pursued":195,"investigation_pursued_pct_of_assigned":26.4},{"year":2023,"reports":1253,"assigned":1253,"investigation_pursued":87,"investigation_pursued_pct_of_assigned":6.9},{"year":2024,"reports":752,"assigned":748,"investigation_pursued":27,"investigation_pursued_pct_of_assigned":3.6},{"year":2025,"reports":617,"assigned":481,"investigation_pursued":18,"investigation_pursued_pct_of_assigned":3.7}]}]},"revisions":{"title":"How much earlier releases were revised","releases_compared":[{"release":"rel-2022Q4","published":null,"data_to":"2022-Q4","quarters_compared":15,"max_abs_quarter_revision":1,"net_revision_all_quarters":0,"quarters_revised_by_more_than_10":{},"max_abs_revision_other_quarters":1,"latest_quarter":{"quarter":"2022-Q4","reports_at_release":2265,"reports_now":2266,"not_provided_at_release":30,"not_provided_now":20,"not_yet_assigned_at_release":23,"not_yet_assigned_now":0,"cyber_at_release":564,"cyber_now":577,"ransomware_at_release":130,"ransomware_now":132}},{"release":"rel-2023Q2","published":"2023-11-01","data_to":"2023-Q2","quarters_compared":18,"max_abs_quarter_revision":505,"net_revision_all_quarters":901,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":8,"latest_quarter":{"quarter":"2023-Q2","reports_at_release":2893,"reports_now":2893,"not_provided_at_release":112,"not_provided_now":98,"not_yet_assigned_at_release":1050,"not_yet_assigned_now":1,"cyber_at_release":1072,"cyber_now":1127,"ransomware_at_release":495,"ransomware_now":511}},{"release":"rel-2023Q3","published":"2024-01-24","data_to":"2023-Q3","quarters_compared":19,"max_abs_quarter_revision":505,"net_revision_all_quarters":895,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":7,"latest_quarter":{"quarter":"2023-Q3","reports_at_release":2715,"reports_now":2711,"not_provided_at_release":61,"not_provided_now":53,"not_yet_assigned_at_release":496,"not_yet_assigned_now":2,"cyber_at_release":689,"cyber_now":689,"ransomware_at_release":205,"ransomware_now":211}},{"release":"rel-2023Q4","published":"2024-04-15","data_to":"2023-Q4","quarters_compared":20,"max_abs_quarter_revision":505,"net_revision_all_quarters":882,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":5,"latest_quarter":{"quarter":"2023-Q4","reports_at_release":3010,"reports_now":3007,"not_provided_at_release":45,"not_provided_now":49,"not_yet_assigned_at_release":464,"not_yet_assigned_now":130,"cyber_at_release":907,"cyber_now":896,"ransomware_at_release":357,"ransomware_now":358}},{"release":"rel-2024Q1","published":"2024-06-11","data_to":"2024-Q1","quarters_compared":21,"max_abs_quarter_revision":505,"net_revision_all_quarters":890,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":4,"latest_quarter":{"quarter":"2024-Q1","reports_at_release":2970,"reports_now":2971,"not_provided_at_release":24,"not_provided_now":23,"not_yet_assigned_at_release":483,"not_yet_assigned_now":210,"cyber_at_release":807,"cyber_now":807,"ransomware_at_release":225,"ransomware_now":223}},{"release":"rel-2024Q2","published":"2024-09-11","data_to":"2024-Q2","quarters_compared":22,"max_abs_quarter_revision":505,"net_revision_all_quarters":891,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":2,"latest_quarter":{"quarter":"2024-Q2","reports_at_release":3064,"reports_now":3063,"not_provided_at_release":37,"not_provided_now":28,"not_yet_assigned_at_release":546,"not_yet_assigned_now":215,"cyber_at_release":887,"cyber_now":904,"ransomware_at_release":217,"ransomware_now":219}},{"release":"rel-2024Q3","published":"2024-11-21","data_to":"2024-Q3","quarters_compared":23,"max_abs_quarter_revision":505,"net_revision_all_quarters":894,"quarters_revised_by_more_than_10":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"max_abs_revision_other_quarters":2,"latest_quarter":{"quarter":"2024-Q3","reports_at_release":3003,"reports_now":3002,"not_provided_at_release":46,"not_provided_now":33,"not_yet_assigned_at_release":691,"not_yet_assigned_now":193,"cyber_at_release":701,"cyber_now":715,"ransomware_at_release":160,"ransomware_now":161}},{"release":"rel-2025Q2","published":"2025-10-10","data_to":"2025-Q2","quarters_compared":26,"max_abs_quarter_revision":3,"net_revision_all_quarters":-4,"quarters_revised_by_more_than_10":{},"max_abs_revision_other_quarters":3,"latest_quarter":{"quarter":"2025-Q2","reports_at_release":3242,"reports_now":3239,"not_provided_at_release":25,"not_provided_now":23,"not_yet_assigned_at_release":427,"not_yet_assigned_now":296,"cyber_at_release":775,"cyber_now":772,"ransomware_at_release":166,"ransomware_now":165}}],"max_not_provided_in_newest_quarter_of_earlier_releases":112,"current_newest_quarter":{"quarter":"2025-Q4","not_provided":649,"reports":3677},"missing_2019_cases":{"releases":["rel-2023Q2","rel-2023Q3","rel-2023Q4","rel-2024Q1","rel-2024Q2","rel-2024Q3"],"shortfall_vs_current_by_quarter":{"2019-Q1":89,"2019-Q3":299,"2019-Q4":505},"reading":"These releases hold fewer 2019 reports than the 2025-2026 releases (for 2019-Q3 and 2019-Q4 also fewer than the Q4 2022 release, which has no 2019-Q1); the shortfall is confined to 2019 quarters."},"newest_quarter_downward_type_revisions":{"values":[{"release":"rel-2022Q4","quarter":"2022-Q4","incident_type":"Other cyber incident","at_release":113,"now":111,"change":-2},{"release":"rel-2022Q4","quarter":"2022-Q4","incident_type":"Other non-cyber incident","at_release":248,"now":244,"change":-4},{"release":"rel-2023Q2","quarter":"2023-Q2","incident_type":"Brute Force","at_release":35,"now":33,"change":-2},{"release":"rel-2023Q2","quarter":"2023-Q2","incident_type":"Hardware/software misconfiguration","at_release":107,"now":59,"change":-48},{"release":"rel-2023Q2","quarter":"2023-Q2","incident_type":"Other non-cyber incident","at_release":358,"now":352,"change":-6},{"release":"rel-2023Q3","quarter":"2023-Q3","incident_type":"Hardware/software misconfiguration","at_release":98,"now":88,"change":-10},{"release":"rel-2023Q3","quarter":"2023-Q3","incident_type":"Other cyber incident","at_release":157,"now":151,"change":-6},{"release":"rel-2023Q3","quarter":"2023-Q3","incident_type":"Other non-cyber incident","at_release":372,"now":371,"change":-1},{"release":"rel-2023Q3","quarter":"2023-Q3","incident_type":"Phishing","at_release":233,"now":230,"change":-3},{"release":"rel-2023Q4","quarter":"2023-Q4","incident_type":"Data posted or faxed to incorrect recipient","at_release":178,"now":176,"change":-2},{"release":"rel-2023Q4","quarter":"2023-Q4","incident_type":"Hardware/software misconfiguration","at_release":87,"now":80,"change":-7},{"release":"rel-2023Q4","quarter":"2023-Q4","incident_type":"Malware","at_release":38,"now":37,"change":-1},{"release":"rel-2023Q4","quarter":"2023-Q4","incident_type":"Other cyber incident","at_release":174,"now":165,"change":-9},{"release":"rel-2023Q4","quarter":"2023-Q4","incident_type":"Phishing","at_release":301,"now":298,"change":-3},{"release":"rel-2024Q1","quarter":"2024-Q1","incident_type":"Other cyber incident","at_release":171,"now":170,"change":-1},{"release":"rel-2024Q1","quarter":"2024-Q1","incident_type":"Ransomware","at_release":225,"now":223,"change":-2},{"release":"rel-2024Q1","quarter":"2024-Q1","incident_type":"Unauthorised access","at_release":356,"now":354,"change":-2},{"release":"rel-2024Q2","quarter":"2024-Q2","incident_type":"Hardware/software misconfiguration","at_release":89,"now":82,"change":-7},{"release":"rel-2024Q2","quarter":"2024-Q2","incident_type":"Other non-cyber incident","at_release":404,"now":398,"change":-6},{"release":"rel-2024Q2","quarter":"2024-Q2","incident_type":"Unauthorised access","at_release":352,"now":350,"change":-2},{"release":"rel-2024Q3","quarter":"2024-Q3","incident_type":"Hardware/software misconfiguration","at_release":189,"now":182,"change":-7},{"release":"rel-2024Q3","quarter":"2024-Q3","incident_type":"Other non-cyber incident","at_release":462,"now":455,"change":-7},{"release":"rel-2025Q2","quarter":"2025-Q2","incident_type":"Data emailed to incorrect recipient","at_release":625,"now":624,"change":-1},{"release":"rel-2025Q2","quarter":"2025-Q2","incident_type":"Malware","at_release":23,"now":22,"change":-1},{"release":"rel-2025Q2","quarter":"2025-Q2","incident_type":"Other cyber incident","at_release":176,"now":174,"change":-2},{"release":"rel-2025Q2","quarter":"2025-Q2","incident_type":"Ransomware","at_release":166,"now":165,"change":-1}],"instances":26,"releases_with_one":8,"releases_compared":8,"largest":{"release":"rel-2023Q2","quarter":"2023-Q2","incident_type":"Hardware/software misconfiguration","at_release":107,"now":59,"change":-48},"largest_by_type":{"Brute Force":2,"Data emailed to incorrect recipient":1,"Data posted or faxed to incorrect recipient":2,"Hardware/software misconfiguration":48,"Malware":1,"Other cyber incident":9,"Other non-cyber incident":7,"Phishing":3,"Ransomware":2,"Unauthorised access":2},"by_release":[{"release":"rel-2022Q4","quarter":"2022-Q4","named_types_revised_up_total":17,"named_types_revised_down_total":6,"not_provided_at_release":30,"not_provided_now":20},{"release":"rel-2023Q2","quarter":"2023-Q2","named_types_revised_up_total":70,"named_types_revised_down_total":56,"not_provided_at_release":112,"not_provided_now":98},{"release":"rel-2023Q3","quarter":"2023-Q3","named_types_revised_up_total":24,"named_types_revised_down_total":20,"not_provided_at_release":61,"not_provided_now":53},{"release":"rel-2023Q4","quarter":"2023-Q4","named_types_revised_up_total":15,"named_types_revised_down_total":22,"not_provided_at_release":45,"not_provided_now":49},{"release":"rel-2024Q1","quarter":"2024-Q1","named_types_revised_up_total":7,"named_types_revised_down_total":5,"not_provided_at_release":24,"not_provided_now":23},{"release":"rel-2024Q2","quarter":"2024-Q2","named_types_revised_up_total":23,"named_types_revised_down_total":15,"not_provided_at_release":37,"not_provided_now":28},{"release":"rel-2024Q3","quarter":"2024-Q3","named_types_revised_up_total":26,"named_types_revised_down_total":14,"not_provided_at_release":46,"not_provided_now":33},{"release":"rel-2025Q2","quarter":"2025-Q2","named_types_revised_up_total":4,"named_types_revised_down_total":5,"not_provided_at_release":25,"not_provided_now":23}],"reading":"In all 8 earlier releases compared, at least one named incident type has fewer reports for that release's newest quarter in the current file than at first release (26 release-type pairs; the largest fall was 48 reports, Hardware/software misconfiguration in 2023-Q2). Later releases therefore do not only add to newest-quarter type counts. by_release gives, for each release, the named-type revisions up and down and the \"Not Provided\" count at release and now."},"retroactive_recoding":{"quarters_in_every_release":["2019-Q2","2022-Q4"],"by_release":[{"release":"rel-2022Q4","reports":37129,"cyber_ico":8265,"unauthorised_access_coded_cyber":983},{"release":"rel-2023Q2","reports":36325,"cyber_ico":8442,"unauthorised_access_coded_cyber":1199},{"release":"rel-2023Q3","reports":36326,"cyber_ico":8442,"unauthorised_access_coded_cyber":1200},{"release":"rel-2023Q4","reports":36326,"cyber_ico":8442,"unauthorised_access_coded_cyber":1200},{"release":"rel-2024Q1","reports":36324,"cyber_ico":8442,"unauthorised_access_coded_cyber":1200},{"release":"rel-2024Q2","reports":36325,"cyber_ico":8442,"unauthorised_access_coded_cyber":1200},{"release":"rel-2024Q3","reports":36323,"cyber_ico":8442,"unauthorised_access_coded_cyber":1200},{"release":"rel-2025Q2","reports":37129,"cyber_ico":8584,"unauthorised_access_coded_cyber":1228},{"release":"current","reports":37129,"cyber_ico":8584,"unauthorised_access_coded_cyber":1228}],"example_unauthorised_access_coded_cyber":{"quarter":"2021-Q2","fy2021_22_table":63,"rel-2022Q4":62,"rel-2023Q2":137,"rel-2023Q3":137,"rel-2023Q4":137,"rel-2024Q1":137,"rel-2024Q2":137,"rel-2024Q3":137,"rel-2025Q2":137,"current":137},"reading":"The ICO recoded historic reports between releases: the number of Unauthorised access reports coded Cyber for the same past quarters changed between the Q4 2022 and Q2 2023 releases and has been stable since. The current file reflects the ICO's latest coding."},"reading":"Apart from the 2019 shortfall in the releases listed under missing_2019_cases, quarter totals move by only a few reports between releases. Incident-type, category and outcome coding for the newest quarter is revised more. 2025-Q4 has 649 \"Not Provided\" types at first release against at most 112 in the newest quarter of any earlier release compared, so type-level comparisons involving it are treated as provisional.","releases_note":"8 earlier row-level releases are compared: 7 with publication dates from November 2023 to October 2025, plus the Q4 2022 release, whose publication date is not known.","caveats":["Releases for data to 2024-Q4 and 2025-Q1 could not be retrieved from the ICO (see manifest not_retrieved).","Three releases (rel-2023Q4, rel-2024Q1, rel-2024Q3) restart BI numbering from 2022; cases were identified with the composite key described in meta."]},"classification_change_fy2021_22":{"title":"Hardware/software misconfiguration moved from the cyber block to Non Cyber","values":[{"table":"agg-FY2122Q1","period":"01/04/2021 - 30/06/2021","calendar_quarter":"2021-Q2","aggregate_total":2552,"aggregate_cyber":688,"aggregate_cyber_share_pct":27,"aggregate_misconfiguration":45,"aggregate_misconfiguration_category":["cyber"],"aggregate_cryptographic_flaw":2,"row_level_now_total":2544,"row_level_now_cyber":724,"row_level_now_cyber_share_pct":28.5,"row_level_now_misconfiguration":47},{"table":"agg-FY2122Q2","period":"01/07/2021 - 30/09/2021","calendar_quarter":"2021-Q3","aggregate_total":2431,"aggregate_cyber":714,"aggregate_cyber_share_pct":29.4,"aggregate_misconfiguration":56,"aggregate_misconfiguration_category":["cyber"],"aggregate_cryptographic_flaw":0,"row_level_now_total":2409,"row_level_now_cyber":671,"row_level_now_cyber_share_pct":27.9,"row_level_now_misconfiguration":56}],"reading":"The ICO's FY2021/22 aggregate tables list Hardware/software misconfiguration (and Cryptographic flaw) under \"Cyber security incidents\"; every row-level release codes them Non Cyber. The cyber share for the same quarter therefore differs by definition, not by data."}},"seriesBreaks":[{"id":"old_series","what":"Pre-2019 ICO tables (financial years 2013/14 to Q1 2018/19) use DPA 1998-era categories (for example \"Other principle 7 failure\"), different sector lists and financial-year quarters.","handling":"Archived in raw/old-series for provenance; not parsed into the dataset and never joined to the 2019+ series."},{"id":"2019_q1","what":"ICO: \"The data starts at Q2 2019 as incidents were recorded differently prior to this period.\" The file nonetheless contains 2019-Q1; it is shown but flagged.","handling":"Kept in the quarterly series with a flag; 2019 annual total also given for Q2-Q4 only; growth windows start in 2021."},{"id":"unauthorised_access_coding","what":"The ICO coded Unauthorised access as Cyber in every 2019-Q1 and 2019-Q2 report (88.8% across 2019) but in a minority each year from 2020 (41.2% in 2020, falling to 3.8% in 2024; 5.6% in 2025). The data cannot show whether this reflects a coding change or a change in the kind of unauthorised access reported. See unauthorised_access_coding.","handling":"ICO category shares shown as published and alongside a constant-definition always-cyber series; type-level counts combine both categories."},{"id":"misconfiguration_category","what":"Hardware/software misconfiguration and Cryptographic flaw sit in the cyber block of the FY2021/22 aggregate tables but are Non Cyber in every row-level release. Misconfiguration first appears in 2019-Q3.","handling":"Row-level coding used throughout; the aggregate tables are kept in a separate dataset table and not joined."},{"id":"general_business","what":"ICO: \"In late 2019 we moved away from recording cases as 'general business', and tried to be more specific.\"","handling":"General business trends before 2020 are not interpreted."},{"id":"decision_definitions","what":"ICO: definitions of \"informal action taken\" and \"no further action\" changed in April 2021.","handling":"Only \"Investigation pursued\" is used, and only as a share of assigned outcomes."},{"id":"lockdown","what":"ICO: \"substantial drop in reporting in Q2 2020 which is likely a result of the first national UK coronavirus lockdown\".","handling":"Flagged; 2020 not used as a base year."},{"id":"latest_quarter","what":"2025-Q4 is a first release: 649 \"Not Provided\" incident types, and many outcomes not yet assigned.","handling":"Totals used; type-level 2025 results cross-checked on Q1-Q3 only."},{"id":"bi_references","what":"BI64329 appears twice with different details (2024-Q4 and 2025-Q1); three earlier releases restart BI numbering in 2022.","handling":"Cases keyed on BI reference plus quarter and all case-level fields (see meta.case_definition)."},{"id":"retroactive_recoding","what":"Historic reports are recoded between releases (for example Unauthorised access coded Cyber in 2021-Q2: see revisions.retroactive_recoding).","handling":"Only the current release is analysed; earlier releases are used to measure revisions, never mixed into the series."},{"id":"missing_2019_cases","what":"ICO releases published November 2023 to November 2024 hold fewer 2019 reports (2019-Q1, Q3 and Q4) than the Q4 2022 and 2025-2026 releases.","handling":"Documented; the current release (which includes them) is used."},{"id":"page_text","what":"The ICO page lists \"11 March 2025 - Data updated to Q4 2025\" and its body text still says \"up to Q2 2025\"; the file is dated 11 March 2026.","handling":"Publication date taken as 11 March 2026."}],"whatThisDataIsNot":["Reported breaches only. The ICO: the data \"contains only the data security incidents that were discovered and then reported to the ICO\". Undiscovered and unreported incidents are absent.","Only notifiable personal-data breaches. ICO guidance: \"If a risk is likely, you must notify the ICO; if a risk is unlikely, you don't have to report it.\" Incidents with no personal data, or judged unlikely to pose a risk, are not in it.","Not every report. ICO: \"some cases are transferred to a separate system for review. As a result, these cases, which may include some of the larger and more serious breaches, are not included within this data.\"","Not a count of organisations or incidents. The unit is a report; there is no organisation identifier, so repeat reporters and many reports arising from one supplier incident cannot be distinguished.","Sector and incident type are assigned by the ICO as a best fit, one type per report (the most significant), not chosen by the reporting organisation.","A point-in-time record: ICO: \"Data presented is generally based on the information provided when an organisation initially reports a breach.\" People affected are the reporter's initial estimate, in bands.","Not a rate. There are no denominators (organisations per sector, records held), so counts and shares cannot rank how safe a sector is.","Not the ICO annual report figure. The annual report counts \"data breaches reported\" per financial year on a basis the page does not define; the two are compared only as a cross-check.","No 2026 data: the latest published quarter is 2025-Q4."],"validation":[{"check":"ICO annual report 2025/26, performance overview: \"Data breaches reported\" 12,412 in 2024/25 and 17,431 in 2025/26.","source":"https://ico.org.uk/about-the-ico/our-information/annual-reports/information-commissioners-annual-report-202526/performance-overview/ (raw/context)","this_dataset":{"april_2024_to_march_2025":12301,"as_pct_of_annual_report_2024_25":99.1},"reading":"The quarterly file gives 12,301 reports for April 2024 to March 2025, 99.1% of the annual report's 12,412; the bases differ (for example, the trends data excludes cases moved to a separate system). The annual report's 17,431 for April 2025 to March 2026 includes January-March 2026, which the quarterly file does not yet cover; no quarterly figure for 2026 is derived from it."}],"context":{"title":"Cyber security breaches survey 2025/2026 (DSIT and Home Office), context only","url":"https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026","published":"2026-04-30","fieldwork":"August to December 2025","licence":"Open Government Licence v3.0","not_merged_because":"Different measure: a sample survey of organisations' own experience over 12 months, not reports received by the regulator. Its percentages and the ICO counts are never combined or compared as like-for-like.","headlines":["43% of businesses and 28% of charities reported having experienced any kind of cyber security breach or attack in the last 12 months (approximately 612,000 businesses and 57,000 charities).","Business prevalence was in line with the previous year (43% in 2024/2025), after falling from 50% in 2023/2024.","Phishing was the most prevalent type (38% of businesses, 25% of charities).","Ransomware attacks among businesses: 1%, down from 3% in both 2024/2025 and 2023/2024.","19% of businesses and 14% of charities were victims of at least one cyber crime in the past year.","Controls among businesses: updated malware protection 81% of businesses; backing up data securely via a cloud service 74% of businesses; two-factor authentication 47% of businesses.","Formal incident response plans: 25% of businesses and 19% of charities.","40% of businesses and 36% of charities that identified breaches reported their most disruptive breach outside the organisation.","Among charities reporting externally (beyond provider-only cases), the ICO (16%) was the most commonly mentioned destination."],"source_file":"raw/context/csbs-2025-2026-extract.txt"},"originality":{"searched":"2026-09-19","existing":[{"who":"ICO dashboard (Power BI) and XLSX","url":"https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/","covers":"Interactive filters by quarter, sector and type; single latest release; no revision history or constant-definition series."},{"who":"Data Protection Network, \"What data breach trends tell us\" (April 2026)","url":"https://dpnetwork.org.uk/data-breach-trends/","covers":"Q4 2025 headline figures (total, cyber/non-cyber split, outcomes, people affected, time to report). No sector x type time series, no ransomware by sector, no dataset."},{"who":"The Record (Recorded Future News), 3 October 2024","url":"https://therecord.media/uk-ico-ransomware-investigations-data","covers":"Ransomware reports and ICO investigations. Its text gives 1,253 ransomware incidents reported in 2023, of which 87 were investigated; 440 in H1 2024, of which 19 were investigated; and 605 in 2019 and 2020, with all but three investigated. Its chart has no value labels. No sector breakdown."},{"who":"DAC Beachcroft, \"Ransomware and the ICO: Examining enforcement trends\", 4 October 2024","url":"https://www.dacbeachcroft.com/en/What-we-think/Ransomware-and-the-ICO-examining-enforcement-trends","covers":"Ransomware report totals from 2019 to H1 2024 (3,760 in all; \"from 158 in that first year, to 723 in 2021, up to 1,253 in 2023\") and the ICO enforcement angle. No sector breakdown."},{"who":"Mailock (formerly Beyond Encryption), analysis of 2023 ICO data","url":"https://www.mailock.com/blog/data-security-an-analysis-of-the-latest-ico-findings","covers":"2023 totals, top types and sectors, data types and time to report. Single year; no dataset."},{"who":"Kaggle re-host of the ICO file (listed as \"ICO Data Security Incidents\"; URL omitted because it contains an individual's username)","url":null,"covers":"Raw ICO rows re-hosted; no case collapsing or analysis."},{"who":"ICO, \"Insider threat of students leading to increasing number of cyber attacks in schools\" (September 2025)","url":"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/09/insider-threat-of-students-leading-to-increasing-number-of-cyber-attacks-in-schools/","covers":"Education-sector insider breach reports only."},{"who":"Apricorn FOI study via SecurityBrief (2025)","url":"https://securitybrief.co.uk/story/more-than-2-400-public-sector-data-breaches-reported-in-uk-2024","covers":"Public-sector breaches from FOI requests, not ICO trend data."}],"consistency_checks":["DAC Beachcroft's ransomware counts (158 in 2019, 723 in 2021, 1,253 in 2023) equal this study's report counts for the same years.","The Record's 1,253 ransomware incidents in 2023, of which 87 were investigated, equal this study's 2023 ransomware report count and its \"Investigation Pursued\" count for 2023 ransomware reports.","The Record's 605 ransomware incidents in 2019 and 2020, with all but three investigated, match this study: 158 + 447 = 605 reports, of which 156 + 446 = 602 are recorded as \"Investigation Pursued\".","Data Protection Network's Q4 2025 figures (+16% year on year; 23% cyber) match this study's 2025-Q4 vs 2024-Q4 change and ICO-coded cyber share."],"absence_note":"Spot searches on 2026-09-19 found no other published analysis offering a 2019-2025 sector x incident type series, ransomware by sector with n, a constant-definition cyber series or a revision analysis. We found none; this rests on spot searches, not an exhaustive review.","what_this_adds":["Full 2019-2025 quarterly series by sector x incident type as a downloadable CSV (CC BY 4.0), with each finding traceable to dataset rows.","Ransomware by sector: counts and share of each sector's own reports, with n.","Explicit series-break handling: the change in how Unauthorised access reports are split between Cyber and Non Cyber, the misconfiguration reclassification, and a constant-definition cyber series.","Revision analysis across eight earlier ICO releases, showing how far the newest quarter changes after first publication.","Growth windows with a minimum base and a robustness check that excludes the provisional latest quarter."]},"planningNotes":[{"topic":"Backups and recovery","data_point":"ransomware_over_time; data_subjects_affected","evidence":"Ransomware reports fell to 617 in 2025 from 1,253 in 2023, but in 2024-2025 11.1% of ransomware reports with a known count were estimated at the time of reporting to affect 10,000 or more people, against 3.0% of all reports.","note":"Plan recovery that does not depend on the attacked systems: keep offline or immutable backup copies, and test restores against an agreed recovery time.","guidance":["https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ransomware-and-data-protection-compliance/"]},{"topic":"Email and document handling","data_point":"notable_2025_2026.types_at_series_high","evidence":"Reached their highest yearly count in 2025: data emailed to incorrect recipient 2,459; failure to redact 886; failure to use bcc 434.","note":"Checks at the point of sending (recipient confirmation, send delay, bcc defaults, redaction review) target these report types directly.","guidance":[]},{"topic":"Configuration","data_point":"fastest_growing_types","evidence":"Hardware/software misconfiguration reports rose from 208 in 2021 to 422 in 2025 (102.9%), after 478 in 2024.","note":"Permission reviews, change control and configuration baselines for file shares, storage and cloud services address this category.","guidance":[]},{"topic":"Phishing","data_point":"notable_2025_2026.types_at_series_high","evidence":"Phishing reports (1,526) were at their highest yearly count in 2025; on a Q1-Q3 basis they changed 1.8%.","note":"Multi-factor authentication and a clear internal route for reporting suspicious messages limit what a captured password can reach.","guidance":[]},{"topic":"Unauthorised access","data_point":"notable_2025_2026.types_at_series_high; unauthorised_access_coding","evidence":"Unauthorised access reports (1,597) were at their highest yearly count in 2025 (on a Q1-Q3 basis they changed 21.1%), but the ICO coded 1,507 of them as non-cyber. The ICO uses this type both where an individual has unlawfully accessed or disclosed information and where a third party has forcibly accessed a system.","note":"The type also covers people unlawfully accessing or disclosing information, so role-based access, access logging and staff guidance on accessing and disclosing personal data may also be worth reviewing, alongside multi-factor authentication.","guidance":[]},{"topic":"Reporting readiness","data_point":"time_to_report","evidence":"63.4% of 2025 reports were recorded as made within 72 hours of discovery (see the ICO caveat on default times).","note":"A written incident response plan with named roles and notification steps supports reporting within 72 hours.","guidance":["https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/"]}],"page":{"status":"Publication-ready text after the 2026-09-19 verification fixes and the follow-up must-fix pass (see data/research/ico-breach-trends-2026/FIXES.md); not yet published.","rule":"Every number in this block appears in the JSON fields its refs name; build.py fails the build otherwise.","attribution":"Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0.","dateNote":"The ICO page lists the update as 11 March 2025; the file is dated 11 March 2026.","caveatsUpFront":["Reported breaches only. The ICO: the data \"contains only the data security incidents that were discovered and then reported to the ICO\". Undiscovered and unreported incidents are absent.","Not a count of organisations or incidents. The unit is a report; there is no organisation identifier, so repeat reporters and many reports arising from one supplier incident cannot be distinguished.","Not a rate. There are no denominators (organisations per sector, records held), so counts and shares cannot rank how safe a sector is.","2025-Q4 is a first release: 649 of its reports have no incident type yet, so type-level results that depend on it are marked provisional."],"summary":{"text":"This study analyses 77,222 personal data breach reports made to the Information Commissioner's Office (ICO) from 2019 to 2025, using the ICO's published data. Reports reached 13,457 in 2025, 10.3% more than in 2024 and the highest yearly total in the series. The ICO coded 23.4% of 2025 reports as cyber incidents; the most common single type was personal data emailed to the wrong recipient (2,459 reports). Ransomware reports peaked at 1,253 in 2023 and fell to 617 in 2025, a fall that also holds without the incomplete 2025-Q4. 63.4% of 2025 reports were recorded as made within 72 hours of discovery. The figures count reports, not breaches, and the latest quarter (2025-Q4) is a first release with incomplete incident-type coding.","refs":["builtFrom.reports","meta.quarters","findings.totals_by_year.values[year=2025]","findings.totals_by_year.values[year=2024]","findings.totals_by_year.highest_year","findings.cyber_share.by_year[year=2025]","findings.types_by_year.largest_type_2025","findings.ransomware_over_time.peak_year","findings.ransomware_over_time.by_year[year=2025]","findings.notable_2025_2026.items[id=ransomware_2025]","findings.time_to_report.by_year[group=2025]","definitions.notification_window_hours","definitions.unit","findings.notable_2025_2026.items[id=latest_quarter_incomplete]"],"words":121},"keyFindings":[{"id":"reports-2025-highest","text":"The ICO received 13,457 personal data breach reports in 2025, 10.3% more than in 2024 (12,195) and the most of any calendar year from 2019 to 2025. Reports have risen every year since 2022, the lowest year in the series (8,798).","refs":["findings.totals_by_year.values[year=2025]","findings.totals_by_year.values[year=2024]","findings.totals_by_year.values[year=2022]","findings.totals_by_year.highest_year","findings.totals_by_year.lowest_year","findings.totals_by_year.rose_every_year_since","meta.quarters"]},{"id":"mostly-non-cyber","text":"Most reports are not cyber incidents. The ICO coded 23.4% of 2025 reports as cyber (3,153 of 13,457), down from 30.0% in 2023, the highest year for that share. The most common single incident type in 2025 was personal data emailed to the wrong recipient: 2,459 reports, 18.3% of the year's total and its highest yearly count in the series.","refs":["findings.cyber_share.by_year[year=2025]","findings.cyber_share.by_year[year=2023]","findings.cyber_share.highest_year_ico","findings.types_by_year.values[incident_type=Data emailed to incorrect recipient]","findings.types_by_year.largest_type_2025","findings.notable_2025_2026.items[id=types_at_series_high]"]},{"id":"ransomware-fell","text":"Ransomware reports peaked at 1,253 in 2023 and fell to 752 in 2024 and 617 in 2025, when they were 4.6% of all reports. The fall does not rest on the incomplete 2025-Q4: over the first three quarters, reports fell from 603 in 2024 to 469 in 2025. In 2024-2025, 11.1% of ransomware reports with a known count were estimated at the time of reporting to affect 10,000 or more people, against 3.0% of all reports.","refs":["findings.ransomware_over_time.peak_year","findings.ransomware_over_time.by_year[year=2024]","findings.ransomware_over_time.by_year[year=2025]","findings.notable_2025_2026.items[id=ransomware_2025]","findings.data_subjects_affected.by_type_2024_2025[group=Ransomware]","findings.data_subjects_affected.by_type_2024_2025[group=all reports]","definitions.large_band_people"]},{"id":"ransomware-by-sector","text":"Retail and manufacture made the most ransomware reports in 2025: 227 of 617 (36.8%). Ransomware was 15.2% of that sector's own 1,497 reports, and the sector also made the most ransomware reports in 2024-2025 and across 2019-2025. Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.","refs":["findings.ransomware_by_sector.periods[period=2025].sectors[sector=Retail and manufacture]","findings.ransomware_by_sector.periods[period=2025].ransomware_total","findings.ransomware_by_sector.periods[period=2025].top_by_count","findings.ransomware_by_sector.periods[period=2024-2025].top_by_count","findings.ransomware_by_sector.periods[period=2019-2025 (all quarters in file)].top_by_count","findings.ransomware_by_sector.caveats"]},{"id":"fastest-growing-types","text":"Among named incident types with at least 100 reports in 2021, the fastest rises to 2025 were data of the wrong data subject shown in a client portal (103 to 228, up 121.4%), failure to redact (412 to 886, up 115.0%) and hardware or software misconfiguration (208 to 422, up 102.9%). Rises in report counts can reflect more incidents, more reporting or changes in coding; this data cannot separate them.","refs":["findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Data of wrong data subject shown in client portal]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Failure to redact]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Hardware/software misconfiguration]","findings.fastest_growing_types.min_base","findings.fastest_growing_types.windows[window=2021 to 2025].fastest_growing_named_types","findings.fastest_growing_types.caveats"]},{"id":"reporting-speed-and-outcomes","text":"63.4% of 2025 reports were recorded as made within 72 hours of discovery, and 19.0% after more than a week. Of ransomware reports with an outcome recorded, the share recorded as \"Investigation Pursued\" was 3.7% in 2025 (18 of 481), 3.6% in 2024 and 6.9% in 2023; the ICO notes that this outcome \"may not necessarily lead to a full investigation\". 22.0% of 2025 ransomware reports had no outcome recorded yet, so the 2025 share is provisional.","refs":["findings.time_to_report.by_year[group=2025]","definitions.notification_window_hours","findings.ico_decision.by_year_ransomware[group=2025 ransomware]","findings.ico_decision.by_year_ransomware[group=2024 ransomware]","findings.ico_decision.by_year_ransomware[group=2023 ransomware]","findings.ico_decision.caveats"]}],"sections":[{"id":"overall-trend","heading":"Overall trend","text":"The ICO's data security incident trends file holds 77,222 breach reports from 2019-Q1 to 2025-Q4. Yearly totals ranged from 8,798 in 2022, the lowest year, to 13,457 in 2025, and have risen every year since 2022. The 2019 total (12,259) includes 2019-Q1, which the ICO says was recorded differently; 2019-Q2 to 2019-Q4 alone come to 8,887. The ICO says a substantial drop in 2020-Q2 was \"likely a result of the first national UK coronavirus lockdown\". The highest quarter was 2025-Q4, with 3,677 reports, but it is a first release and its coding is less complete than for earlier quarters. As a cross-check, the file gives 12,301 reports for April 2024 to March 2025, 99.1% of the 12,412 data breaches reported in the ICO's annual report for 2024/25; the two use different bases. These are counts of reports received, not of breaches that occurred, and they are not rates.","refs":["builtFrom.reports","meta.quarters","findings.totals_by_year.lowest_year","findings.totals_by_year.values[year=2025]","findings.totals_by_year.rose_every_year_since","findings.totals_by_year.values[year=2019]","findings.totals_by_quarter.caveats","findings.totals_by_quarter.highest_quarter","validation[0]","whatThisDataIsNot","definitions.unit"]},{"id":"cyber-and-non-cyber","heading":"Cyber and non-cyber incidents, including human error","text":"The ICO codes each report as cyber or non-cyber. In 2025 it coded 3,153 of 13,457 reports (23.4%) as cyber and 76.6% as non-cyber. The ICO-coded cyber share was 19.1% in 2019, peaked at 30.0% in 2023 and then fell back. The ICO coded unauthorised access as cyber in every 2019-Q1 and 2019-Q2 report (88.8% across 2019) but in a minority each year from 2020 (41.2% in 2020, falling to 3.8% in 2024; 5.6% in 2025), and the data cannot show whether this reflects a coding change or a change in the kind of unauthorised access reported. So this study also shows a constant-definition share: reports of the incident types the ICO always codes as cyber, as a share of reports with an incident type recorded. It was 13.9% in 2019, 29.3% in 2023 and 24.2% in 2025. Non-cyber reports include everyday handling errors. In 2025, data emailed to the wrong recipient (2,459 reports), failure to redact (886), failure to use bcc (434) and verbal disclosure of personal data (348) were each at their highest yearly count in the series, although the leads for failure to use bcc (18 reports) and verbal disclosure (9) are small while 2025-Q4 is provisional. The ICO says its cyber and non-cyber split is under review and should be read with caution. Reports with no incident type count as non-cyber in that split, including 649 in 2025-Q4.","refs":["findings.cyber_share.by_year[year=2025]","findings.cyber_share.by_year[year=2024]","findings.cyber_share.by_year[year=2023]","findings.cyber_share.by_year[year=2019]","findings.cyber_share.highest_year_ico","findings.cyber_share.definitions","findings.unauthorised_access_coding.reading","findings.unauthorised_access_coding.values","findings.unauthorised_access_coding.lowest_year_from_2020","findings.notable_2025_2026.items[id=types_at_series_high]","findings.cyber_share.caveats","findings.cyber_share.not_provided_coding"]},{"id":"ransomware","heading":"Ransomware by year and sector","text":"Ransomware reports rose from 158 in 2019 to a peak of 1,253 in 2023, then fell to 752 in 2024 and 617 in 2025, when they were 4.6% of all reports and 19.6% of ICO-coded cyber reports. The fall also shows on the first three quarters alone (603 in 2024, 469 in 2025), so it does not rest on the incomplete 2025-Q4. The peak quarter, 2023-Q2, had 511 ransomware reports, 201 of them from finance, insurance and credit; the data has no organisation identifier, so it cannot show whether several reports stem from one underlying incident. By sector, retail and manufacture made the most ransomware reports in 2025, in 2024-2025 and across 2019-2025. In 2025 it made 227 of the 617 reports, and ransomware was 15.2% of the sector's own reports, the highest share among sectors with at least 100 reports. Sectors differ in how readily they detect, assess and report breaches, so a higher count or share can reflect reporting practice as well as the number of incidents.","refs":["findings.ransomware_over_time.by_year[year=2019]","findings.ransomware_over_time.peak_year","findings.ransomware_over_time.by_year[year=2024]","findings.ransomware_over_time.by_year[year=2025]","findings.notable_2025_2026.items[id=ransomware_2025]","findings.ransomware_over_time.peak_quarter","findings.ransomware_over_time.caveats","findings.ransomware_by_sector.periods[period=2025].top_by_count","findings.ransomware_by_sector.periods[period=2024-2025].top_by_count","findings.ransomware_by_sector.periods[period=2019-2025 (all quarters in file)].top_by_count","findings.ransomware_by_sector.periods[period=2025].sectors[sector=Retail and manufacture]","findings.ransomware_by_sector.periods[period=2025].ransomware_total","findings.ransomware_by_sector.periods[period=2025].top_by_share_of_own_reports","findings.ransomware_by_sector.min_n_for_share_ranking","findings.ransomware_by_sector.caveats"]},{"id":"fastest-growing","heading":"Fastest-growing incident types","text":"Among named incident types with at least 100 reports in 2021, the fastest rises to 2025 were data of the wrong data subject shown in a client portal (103 to 228, up 121.4%), failure to redact (412 to 886, up 115.0%), hardware or software misconfiguration (208 to 422, up 102.9%), failure to use bcc (279 to 434, up 55.6%) and phishing (1,045 to 1,526, up 46.0%). The catch-all \"other cyber incident\" type rose faster (297 to 770) but is not ranked. Misconfiguration reports were lower in 2025 (422) than in 2024 (478), and also on the first three quarters (358 in 2024, 329 in 2025). From 2024 to 2025 the largest rises among named types were in unauthorised access (up 20.3%) and failure to redact (up 18.0%). Rises in report counts can reflect more incidents, more reporting or changes in coding, and this data cannot separate them. Falls are less certain, because 649 reports in 2025-Q4 have no incident type yet. Later releases are expected mainly to add to 2025 type counts as the 649 uncoded reports are assigned, but in earlier releases some types' newest-quarter counts were also revised down. Ransomware fell 14.7% from 2021 to 2025 on full years and 12.2% on the first three quarters; loss or theft of devices containing personal data fell 8.3% on full years but went only from 124 to 123 on the first three quarters.","refs":["findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Data of wrong data subject shown in client portal]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Failure to redact]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Hardware/software misconfiguration]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Failure to use bcc]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Phishing]","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Other cyber incident]","findings.fastest_growing_types.min_base","findings.fastest_growing_types.windows[window=2021 to 2025].fastest_growing_named_types","findings.fastest_growing_types.windows[window=2024 to 2025].falls_provisional.checks[incident_type=Hardware/software misconfiguration]","findings.fastest_growing_types.windows[window=2024 to 2025].types[incident_type=Unauthorised access]","findings.fastest_growing_types.windows[window=2024 to 2025].types[incident_type=Failure to redact]","findings.fastest_growing_types.windows[window=2024 to 2025].fastest_growing_named_types","findings.fastest_growing_types.caveats","findings.fastest_growing_types.windows[window=2021 to 2025].falls_provisional","findings.notable_2025_2026.items[id=latest_quarter_incomplete]"]},{"id":"reporting-speed-and-outcomes","heading":"Reporting speed and ICO outcomes","text":"For a notifiable breach, UK GDPR expects the ICO to be told within 72 hours of becoming aware of it, where feasible. 63.4% of 2025 reports were recorded as made within 72 hours of discovery and 19.0% after more than a week. When only a date is given, the ICO enters midnight as the discovery time, which can place some on-time reports outside the window. By type in 2024-2025, 70.1% of reports of data emailed to the wrong recipient were recorded as made within 72 hours, against 61.0% for ransomware and 52.2% for unauthorised access. On outcomes, of ransomware reports with an outcome recorded, the share recorded as \"Investigation Pursued\" was 54.5% in 2021, 6.9% in 2023 and 3.7% in 2025 (18 of 481). Across all 2025 reports with an outcome recorded, the share was 2.0% (207 of 10,552). The ICO says this outcome \"may not necessarily lead to a full investigation\", its outcome definitions changed in April 2021, and 21.6% of all 2025 reports and 22.0% of 2025 ransomware reports had no outcome assigned yet, so the 2025 shares are provisional.","refs":["definitions.notification_window_hours","definitions.notification_note","findings.time_to_report.by_year[group=2025]","findings.time_to_report.caveats","findings.time_to_report.by_type_2024_2025[group=Data emailed to incorrect recipient]","findings.time_to_report.by_type_2024_2025[group=Ransomware]","findings.time_to_report.by_type_2024_2025[group=Unauthorised access]","findings.ico_decision.by_year_ransomware[group=2021 ransomware]","findings.ico_decision.by_year_ransomware[group=2023 ransomware]","findings.ico_decision.by_year_ransomware[group=2025 ransomware]","findings.ico_decision.by_year_all[group=2025]","findings.ico_decision.caveats","definitions.investigation_pursued_share"]},{"id":"what-this-means","heading":"What this means for organisations","framing":"Advice framing only: considerations drawn from the data and from NCSC and ICO guidance, not instructions or legal advice.","links":["https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ransomware-and-data-protection-compliance/","https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks"],"text":"These figures count reports to the regulator; they do not measure the risk to any one organisation. Read alongside official guidance, they point to a few areas worth reviewing. Backup and recovery: ransomware reports fell to 617 in 2025, but in 2024-2025 11.1% of ransomware reports with a known count were estimated at the time of reporting to affect 10,000 or more people, against 3.0% of all reports. It is worth considering recovery that does not depend on the attacked systems, such as offline or immutable backup copies, with restores tested against an agreed recovery time. Email and document handling: data emailed to the wrong recipient, failure to redact and failure to use bcc all reached their highest yearly counts in 2025, so checks at the point of sending (recipient confirmation, a send delay, bcc defaults and a redaction review) may be worth a look. Phishing: phishing reports (1,526) were also at their highest in 2025; multi-factor authentication and a clear internal route for reporting suspicious messages can limit what a captured password can reach. Access controls: unauthorised access reports (1,597) were at their highest in 2025 too, but the ICO coded 1,507 of them as non-cyber (the type also covers people unlawfully accessing or disclosing information), so role-based access, access logging and staff guidance may also be worth reviewing. Configuration: misconfiguration reports rose from 208 in 2021 to 422 in 2025, and permission reviews, change control and configuration baselines for file shares, storage and cloud services are the usual controls to review. For context, the separate Cyber security breaches survey 2025/2026 found two-factor authentication in place at 47% of businesses and a formal incident response plan at 25% of businesses. The NCSC and ICO guidance linked below gives more detail.","refs":["definitions.unit","whatThisDataIsNot","findings.ransomware_over_time.by_year[year=2025]","findings.data_subjects_affected.by_type_2024_2025[group=Ransomware]","findings.data_subjects_affected.by_type_2024_2025[group=all reports]","definitions.large_band_people","findings.notable_2025_2026.items[id=types_at_series_high]","findings.unauthorised_access_coding.values[year=2025]","findings.unauthorised_access_coding.ico_definition","findings.fastest_growing_types.windows[window=2021 to 2025].types[incident_type=Hardware/software misconfiguration]","planningNotes","context.headlines","context.title"]}],"faq":[{"q":"How many data breaches were reported to the ICO in 2025?","refs":["findings.totals_by_year.values[year=2025]","findings.totals_by_year.values[year=2024]","findings.totals_by_year.highest_year","meta.quarters","findings.totals_by_quarter.highest_quarter","whatThisDataIsNot"],"a":"The ICO received 13,457 personal data breach reports in 2025, 10.3% more than in 2024 (12,195) and the most of any calendar year from 2019 to 2025. The busiest quarter was 2025-Q4, with 3,677 reports. These are reports of breaches that organisations discovered and reported to the ICO; they are not a count of all breaches."},{"q":"What is the most common type of personal data breach reported to the ICO?","refs":["findings.types_by_year.values[incident_type=Data emailed to incorrect recipient]","findings.types_by_year.values[incident_type=Other non-cyber incident]","findings.types_by_year.values[incident_type=Unauthorised access]","findings.types_by_year.values[incident_type=Phishing]","findings.cyber_share.by_year[year=2025]"],"a":"In 2025 the most common incident type was data emailed to the wrong recipient, with 2,459 reports (18.3% of the year's reports). Next came the catch-all \"other non-cyber incident\" (1,697), unauthorised access (1,597) and phishing (1,526). The ICO coded 76.6% of 2025 reports as non-cyber."},{"q":"Is ransomware increasing in the UK?","refs":["findings.ransomware_over_time.peak_year","findings.ransomware_over_time.by_year[year=2024]","findings.ransomware_over_time.by_year[year=2025]","findings.notable_2025_2026.items[id=ransomware_2025]","context.headlines","context.not_merged_because","whatThisDataIsNot","context.title"],"a":"Not in reports to the ICO. Ransomware reports peaked at 1,253 in 2023 and fell to 752 in 2024 and 617 in 2025; over the first three quarters they fell from 603 in 2024 to 469 in 2025. The separate Cyber security breaches survey 2025/2026 found ransomware attacks among businesses at 1%, down from 3% in both of the two previous years. The two sources measure different things and are not combined: the survey asks organisations about their own experience, while the ICO data covers only notifiable personal data breaches that were reported."},{"q":"Which sectors report the most ransomware?","refs":["findings.ransomware_by_sector.periods[period=2025].sectors[sector=Retail and manufacture]","findings.ransomware_by_sector.periods[period=2025].ransomware_total","findings.ransomware_by_sector.periods[period=2025].sectors[sector=Finance, insurance and credit]","findings.ransomware_by_sector.periods[period=2025].sectors[sector=Education and childcare]","findings.ransomware_by_sector.periods[period=2025].top_by_count","findings.ransomware_by_sector.caveats","whatThisDataIsNot"],"a":"Retail and manufacture made the most ransomware reports in 2025 (227 of 617), followed by finance, insurance and credit (76) and education and childcare (44). Ransomware was 15.2% of retail and manufacture's own reports. Sectors differ in how readily they detect, assess and report breaches, and the ICO assigns sector as a best fit, so these figures do not show how safe a sector is."},{"q":"How quickly do organisations report breaches to the ICO?","refs":["findings.time_to_report.by_year[group=2025]","findings.time_to_report.by_year[group=2019]","findings.time_to_report.by_year[group=2023]","definitions.notification_window_hours","findings.time_to_report.caveats"],"a":"63.4% of 2025 reports were recorded as made within 72 hours of discovery, and 19.0% after more than a week. The share recorded within 72 hours was 63.3% in 2019 and 57.4% in 2023. When only a date is given, the ICO enters midnight as the discovery time, so some reports made on time may be labelled as late."},{"q":"How often does the ICO investigate a reported breach?","refs":["findings.ico_decision.by_year_all[group=2025]","findings.ico_decision.by_year_ransomware[group=2025 ransomware]","findings.ico_decision.caveats","definitions.investigation_pursued_share"],"a":"Of 2025 reports with an outcome recorded, 2.0% (207 of 10,552) were recorded as \"Investigation Pursued\"; for ransomware reports the share was 3.7% (18 of 481). The ICO says this outcome means a case was passed to its investigations teams and \"may not necessarily lead to a full investigation\". 21.6% of all 2025 reports and 22.0% of 2025 ransomware reports had no outcome assigned yet, so both 2025 shares are provisional."},{"q":"Does the data cover 2026?","refs":["findings.notable_2025_2026.items[id=no_2026_quarters]","validation[0]","meta.quarters"],"a":"No. The latest quarter in the ICO file is 2025-Q4. The ICO page lists the update as 11 March 2025; the file is dated 11 March 2026. The ICO's annual report gives 17,431 data breaches reported in 2025/26, a financial year that includes January to March 2026, but that total uses a different basis and no 2026 quarterly figure is derived from it."},{"q":"Can I download and reuse the data?","refs":["download","meta.dataset_licence","meta.source_licence","attribution"],"a":"Yes. The quarter by sector by incident type table is available as a CSV with 7,619 rows covering 77,222 reports, with a README that gives the attribution and caveats. The derived tables are licensed under CC BY 4.0; the underlying ICO data is under the Open Government Licence v3.0. Please credit: \"Contains information from the Information Commissioner's Office, Data security incident trends (data to Q4 2025, published 11 March 2026), licensed under the Open Government Licence v3.0. Derived tables: CC BY 4.0.\""}]}}